New Android Banking Trojan Deploys AI to Automate Device Navigation
Discovered by Zimperium zLabs, the RedHat malware uses an AI assistant to visually parse app interfaces and bypass layout changes in real time.

Cybersecurity researchers at Zimperium zLabs have identified a novel Android banking trojan named RedHat that employs an integrated artificial intelligence assistant to autonomously navigate and control compromised devices, TechRadar Pro reported .
According to Zimperium, the malware is suspected to be of Chinese origin and spreads through third-party app stores, social media platforms, malvertising, and SMS spam. To execute its automated control routines, the trojan relies on Android's Accessibility permissions.
Like traditional financial trojans, RedHat generates invisible screen overlays over targeted banking applications to harvest login credentials and one-time passwords. However, standard trojans typically rely on hardcoded user interface coordinates, causing automated interaction scripts to fail whenever a financial app updates its visual layout.
RedHat circumvents static coordinate dependencies by capturing the device screen and sending the image to an AI assistant, which analyzes the interface and returns instructions on how to proceed. "RatHat uses AI to intelligently navigate and control the device interface in real-time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation," Zimperium stated.
The trojan also incorporates persistence mechanisms, including the ability to reinstall deleted modules and intercept uninstallation attempts to cancel them while displaying fake error dialogs. Zimperium noted that specific targets and the overall number of compromised devices remain unconfirmed.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


