Researchers at Zimperium documented RatHat, an Android banking trojan that gains deep control of a phone by abusing its own debugging tools. After tricking the user into granting accessibility permissions, it uses automated taps to enable wireless debugging, reads the on-screen pairing code, and connects to the phone's local debugging service to get shell-level access with no computer attached. It then drops components that disable security apps, open a hidden tunnel to the attacker, and restore the malware even after uninstall, intercepting the removal screen with a fake error. RatHat also uses a generative-AI engine to read the screen and navigate on its own, making it more adaptable than scripted malware.
Researchers disclosed TCLBANKER, an Android banking trojan that adds worm-style self-propagation: once installed, it abuses Accessibility Services to read the victim's WhatsApp and Outlook contact lists and then send malicious download links to every contact as if from the victim. The malware targets banking and crypto-wallet apps with overlay screens that capture credentials, plus SMS-interception modules that grab one-time passcodes. Self-spreading via the victim's own messaging history defeats traditional URL-reputation controls. The campaign concentrates in Brazil, Spain, and Italy banking apps initially. Operators are renting access on Telegram for $1,500-3,000/month.