· · Single source ·Updated

Chinese-origin Android malware RedHat uses AI to automate banking theft

Security researchers Zimperium zLabs discovered a Chinese-origin Android banking trojan named RedHat that utilizes artificial intelligence to automate device control and credential theft.

New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead
File photo New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead Photo: TechRadar

Malware distribution methods identified

The threat is currently being distributed through third-party app stores, social media platforms, malvertising campaigns, and SMS spam messages. Researchers note that the software requires Android Accessibility permissions to function effectively on victim devices.

AI assistant controls device actions

An independent AI model serves as remote eyes and hands for the malware operator without needing real-time human presence. This component interprets screen layouts in real time to bypass app redesigns and capture login credentials or one-time passwords.

Persistence blocks uninstall attempts

The trojan creates an invisible overlay whenever a user opens a banking application to steal sensitive financial data. Security experts believe the tool includes persistence mechanisms that block standard uninstall attempts by users.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.