Kurt Knutsson, The CyberGuy, details an “unprecedented cyber incident” where an OpenAI experimental AI model escaped during a security test and autonomously hacked a rival AI startup. Knutsson warns that this event proves AI safety cannot be solved by individual companies in secret and highlights the urgent need for robust guardrails and regulation.
NEWYou can now listen to Fox News articles!
Your Android phone probably holds far more sensitive information than you realize. Banking apps, passwords and security codes can all pass through that little screen in your hand. A newly uncovered Android threat called RatHat wants access to all of it.
Security researchers at Zimperium discovered the malware, which uses generative AI as part of its attack, and found that it can turn permissions you approve into surprisingly deep control of your phone. RatHat can steal banking credentials, intercept authentication codes and even reconstruct a PIN or unlock pattern from where your finger touches the screen. It can also create a persistent connection that may survive after you remove the malicious app.
The attack still needs help from the person holding the phone. RatHat relies heavily on tricking someone into installing a malicious Android app and approving powerful permissions. That gives you several opportunities to stop it before the malware takes over.
Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.
Our free CyberGuy LIVE class Get Better Healthcare With AI has ended, but you can still watch the full replay. Kurt “CyberGuy” Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.
Watch the free replay + downloadable checklist now at CyberGuyLive.com
AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION

RatHat abuses powerful Android settings such as Accessibility permissions and Wireless Debugging to gain deeper control of an infected phone. (Brent Lewin/Bloomberg via Getty Images)
RatHat starts with social engineering. Zimperium says attackers primarily spread it through SMS phishing, malicious advertising and deceptive third-party download sites. The malicious APK may pose as familiar software, including a streaming app or Chrome. That familiar name can lower your guard. A download page might look convincing enough to make you think you are installing a normal app. However, RatHat relies on you manually installing an APK outside Google Play. Once installed, the malicious app pushes you to enable Android’s Accessibility Service. The excuse can vary by region. In some cases, the malware claims the permission will solve a network problem or unlock a financial benefit. Accessibility services perform important legitimate functions on Android. However, they can also give an approved app the ability to inspect what appears on your screen and interact with the interface. RatHat takes advantage of that power to begin changing settings without you doing the work yourself.
Once RatHat gets Accessibility access, it can tap through Android settings to enable Developer Options and Wireless Debugging. It can then read the six-digit ADB pairing code displayed on the phone and connect to the device’s own Android Debug Bridge. No separate computer has to complete the connection. ADB, short for Android Debug Bridge, gives developers powerful tools to test and manage Android devices. RatHat abuses that legitimate feature to establish shell-level access outside the normal Android app sandbox. From there, the malware launches a Go-based agent that can execute system commands. It also starts a reverse-proxy client that creates a persistent connection back to the attacker. Zimperium says that connection can give an operator continued access to the phone’s ADB service. RatHat also brings AI into the process. The malware sends information from Android’s live Accessibility tree to a generative AI assistant. The AI can help determine where an item appears on the screen, read displayed text and tell the malware when to scroll. That makes the attack more adaptable than automation that follows the same fixed sequence every time. We recently saw another Android threat abuse Wireless Debugging in a similar way. RatHat adds AI-assisted navigation and another persistence mechanism to the mix.
After gaining access, RatHat can watch for financial apps and display fake screens over legitimate ones. Those overlays can trick you into entering banking credentials directly into a page controlled by the attacker. Zimperium found RatHat targeting banking and cryptocurrency apps. It also specifically identified overlays aimed at payment services such as WeChat and Alipay. The malware can intercept SMS messages and notification content as well, giving attackers another way to capture one-time passwords and two-factor authentication codes. Then there is the way RatHat watches your fingers. The malware can monitor raw touch coordinates and compare those locations with known keypad layouts. That allows it to reconstruct PINs from where you tap. It can use a similar method to recover Android pattern-lock sequences. Because the malware reads those touch coordinates at a low level, protections that normally hide PIN digits from screen readers do not stop this technique. That means a criminal may never need to see your PIN displayed as text. Your finger movements can give it away.
RatHat also tries to make leaving your phone much harder than getting onto it. Zimperium found that the malware can interfere when you try to uninstall the malicious app. It can cancel the real uninstall process and place a fake Google Play error message on top of the screen. Even if you successfully remove the visible app, another problem remains. RatHat launches a separate native service outside the normal app life cycle. That service can stay behind after the original app disappears. It can then reinstall the malware and restore its permissions. Zimperium also found that RatHat can request Device Admin rights. Those rights give it additional control, including the ability to wipe the device if someone tries to uninstall it. That persistence is why deleting a suspicious app may not be enough once RatHat fully compromises a phone.
Google responded to CyberGuy and says it has not found RatHat on Google Play based on its current detection. The company also says Android users already have protection against known versions of the malware through Google Play Protect. “Based on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services,” a Google spokesperson told CyberGuy. That is reassuring for people who download their apps through Google Play. It also reinforces why keeping Play Protect enabled can add an important layer of defense if a harmful app reaches your phone from another source.
RatHat becomes dangerous after it gains several layers of access. Fortunately, you can break that chain at several points. These steps can reduce your risk and help you respond if something has already gone wrong.
HACKERS HIJACK VERIFIED STREAMING ACCOUNT TO SPREAD MALWARE, RESEARCHERS FIND

RatHat can disguise malicious Android apps as familiar software, making it especially important to install apps through the official Google Play Store. (Firdous Nazir/NurPhoto via Getty Images)
Avoid installing APK files that arrive through text messages, online ads or unfamiliar websites. RatHat relies heavily on persuading people to sideload malicious apps. If a page looks like Google Play but you can see a browser address bar, you are still on a website. Close it and open the actual Google Play Store app. Also question any message that tells you to reinstall Chrome or another app already on your phone. Open Google Play yourself and check the app there instead.
Accessibility access plays a central role in RatHat’s attack. Therefore, treat an unexpected request for that permission as a serious warning. Open Settings and search for Accessibility. Review apps with Accessibility access and remove permission from anything you do not recognize or no longer use. Menu names can vary by Android phone. If a streaming app, browser update or other unrelated app suddenly tells you that Accessibility access is required, do not approve it until you know exactly why.
Most Android users never need Wireless Debugging. RatHat uses it to establish its powerful ADB shell connection. Open Settings and search for Developer options or Wireless debugging. Leave Wireless Debugging turned off unless you have a specific reason to use it. If you discover Developer Options or Wireless Debugging enabled and you do not remember turning them on, take a closer look at the apps and security settings on your phone.
Install strong antivirus software and keep real-time protection enabled. Security software can help detect malicious apps and suspicious activity before they get deeper access to your phone. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
However, detecting RatHat and completely removing it are two different things. Because the malware can leave behind a persistent service after the visible app is removed, we recommend a factory reset if a security scan confirms RatHat has fully infected your phone.
Google says Android users are automatically protected against known versions of RatHat through Google Play Protect, which comes turned on by default on Android devices with Google Play Services. You can still check that it is enabled. Open the Google Play Store > tap your profile picture > Play Protect > Settings. Make sure Scan apps with Play Protect is turned on. You can also enable Improve harmful app detection. This gives Google additional information about unfamiliar apps installed outside Google Play so they can be checked for harmful behavior.
Android’s Advanced Protection can provide another useful barrier on supported devices. Google says it blocks app installations from unknown sources and restricts Accessibility services to verified accessibility tools. It also prevents Play Protect from being turned off while Device protection is active. To turn it on, open Settings > Security & privacy > Advanced Protection > turn on Device protection. Google notes that your phone may need to restart. For someone who rarely sideloads apps, those extra restrictions can remove two of the avenues RatHat relies on.
THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE

Once inside, RatHat can target financial apps and steal sensitive information including bank logins, PINs and authentication codes. (NickyLloyd via Getty Images)
Install Android security updates and app updates when they become available. Updates fix known vulnerabilities and strengthen protections across your phone. RatHat’s documented infection chain depends primarily on malicious downloads and permission abuse, so an Android update alone will not solve the problem. Even so, running current software closes other security gaps that attackers could try to exploit.
RatHat spreads partly through smishing, which is phishing delivered by text message. An urgent message can push you toward a malicious download before you stop to question it. Avoid tapping links in unexpected texts that tell you to install an app or fix a problem on your phone. Instead, open the company’s official app or visit its known website yourself. The same advice applies to online ads offering apps. Malvertising can lead to convincing download pages that have nothing to do with the company they appear to represent.
If antivirus software flags RatHat or you have strong reason to think your phone has been compromised, stop entering passwords and financial information on it. Use another trusted device to change important passwords. Start with your primary email account, since access to email can help an attacker reset other accounts. Then check your bank and credit card accounts for activity you do not recognize. If you spot anything suspicious, contact the financial institution using the number on the back of your card or through its official app.
If RatHat is confirmed, we recommend a factory reset rather than relying on a normal uninstall. RatHat’s separate background component can survive after the visible malicious app disappears. Before resetting the phone, preserve personal photos or documents you know are safe. After the reset, install apps again through Google Play. Avoid reinstalling unfamiliar APK files from an old backup. You should also change credentials from another trusted device before returning to sensitive accounts on the reset phone.
RatHat can target banking credentials and authentication codes, so cleaning the phone should not be the end of your response. Continue reviewing bank statements and login alerts. Also watch for password-reset messages or authentication requests you did not initiate. If you believe personal information beyond your login credentials may have been exposed, consider an identity theft protection service that can help monitor for suspicious activity. Acting quickly can limit the damage if stolen information gets used later.
The AI component makes RatHat unusual, but the attack still begins with something very familiar: getting someone to trust the wrong download and approve a powerful permission. That gives Android users a chance to stop RatHat before it reaches the most damaging stages. Google’s response adds another important piece of reassurance. The company says no apps containing RatHat are currently showing up on Google Play based on its detection, and Play Protect already guards Android users against known versions of the malware. Still, that protection works best when you avoid sideloading questionable apps and pay close attention to powerful permission requests. Keep Play Protect running and add strong antivirus protection to your phone. Wireless Debugging should stay off unless you know exactly why you need it. If RatHat does make it onto a device, do not assume deleting the app solves the problem. A confirmed infection calls for a much more serious cleanup.
Does knowing AI-powered malware like RatHat can quietly take control of your phone make you think twice about installing apps outside Google Play? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Copyright 2026 CyberGuy.com. All rights reserved.




Discount Applied Successfully!
Your savings have been added to the cart.