New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead
- Zimperium zLabs discovered RedHat, a Chinese‑origin Android banking trojan with AI assistant
- AI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesigns
- Distributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attempts
There is an Android malware out there that comes with an AI assistant that tells it what to do. The assistant seems to be independent of the malware’s operator, allowing the tool to work without requiring the operators to be present in real-time.
The malware in question is called RedHat. It was discovered by security researchers Zimperium zLabs, who believe it is of Chinese origin. It is currently being distributed via third-party app stores, social media, malvertising, and SMS spam, and requires Android’s Accessibility permissions to work.
The malware itself is a typical banking trojan – it creates an invisible overlay every time the victim brings up a banking app, capturing login credentials and one-time passwords, and thus giving attackers direct control over people’s banking accounts.
Latest Videos FromTechRadar
AI-powered eyes
But what makes RedHat stand out from a sea of Android banking trojans is its AI-powered component. The model serves as a kind of remote “eyes and hands” for controlling the victim’s phone.
Usually, when criminals develop banking trojans, they need to code exact coordinates of the layout for it to work. They need to code where the password is entered, or where the login button is. If the banking app gets redesigned and changes its layout, the malware breaks.
With AI, that is no longer a problem. RedHat gets a picture of what’s on the screen, sends it to the AI assistant, which then instructs the malware on how to proceed.
“RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation,” Zimperium explained.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The tool also has a few advanced persistence mechanisms, being capable of reinstalling deleted components, and intercepting the uninstall process to cancel it while displaying a fake error message to the victim.
So far, there is no word on who the targets are, or how many people might have been compromised.
Via BleepingComputer
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Zimperium zLabs discovered RedHat, a Chinese‑origin Android banking trojan with AI assistant AI interprets screen layouts in real‑time, enabling credential theft and bypassing app redesigns Distributed via third‑party stores, social media, malvertising, and SMS; persistence blocks uninstall attempts There is an Android malware out there that comes with an AI…
Recent Posts
- Sony Music and UMG say Suno’s new models still violates their copyright
- TP-Link’s budget-friendly Archer AX21 Wi-Fi 6 router drops to $60 in Amazon’s Early Prime Day — but this deal ends soon
- Apple Watch Ultra 4 Review: The Series 12 Is Closing the Gap
- New Android malware can deploy AI to automate device control — and it can even bring itself back from the dead
- The new Resident Evil movie captures the survival horror magic of the games
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023