Researchers report a new Android malware strain dubbed RatHat that combines spyware and backdoor functionality to steal financial-related data from infected devices. Zimperium researchers say the malware also supports remote access capabilities, enabling operators to control compromised phones.

Both outlets describe RatHat as introducing an AI-driven subsystem that assists attackers in automating parts of device interaction after compromise. Bleeping Computer characterizes this component as helping operators navigate or manage devices remotely using AI-assisted behavior, while Infosecurity Magazine emphasizes the malware’s use of AI alongside its goal of extracting financial data.

The reporting focuses on the same core technical capabilities—spyware, backdoors, remote control features, and AI assistance—while differing slightly in emphasis. Infosecurity Magazine leads with the malware’s financial data theft outcome, whereas Bleeping Computer highlights automation of device control as a key differentiator. Neither source provides details about the scale of infections, specific affected regions, or named affected organizations in the provided excerpts.