Chinese-origin Android malware RedHat uses AI to automate banking theft
Security researchers Zimperium zLabs discovered a Chinese-origin Android banking trojan named RedHat that utilizes artificial intelligence to automate device control and credential theft.

Malware distribution methods identified
The threat is currently being distributed through third-party app stores, social media platforms, malvertising campaigns, and SMS spam messages. Researchers note that the software requires Android Accessibility permissions to function effectively on victim devices.
AI assistant controls device actions
An independent AI model serves as remote eyes and hands for the malware operator without needing real-time human presence. This component interprets screen layouts in real time to bypass app redesigns and capture login credentials or one-time passwords.
Persistence blocks uninstall attempts
The trojan creates an invisible overlay whenever a user opens a banking application to steal sensitive financial data. Security experts believe the tool includes persistence mechanisms that block standard uninstall attempts by users.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.