AI News Feed
Market watch
Cybersecurity

Zimperium Finds RedHat Android Trojan That Uses AI to Control Infected Devices

Zimperium zLabs has identified RedHat, a Chinese-origin Android banking trojan that uses an AI assistant to read screen layouts in real time, steal credentials and one-time passwords, and resist removal, according to TechRadar.

The malware is being distributed through third-party app stores, social media, malvertising, and SMS spam, TechRadar reported, citing BleepingComputer. It requires Android’s Accessibility permissions to operate. Once active, RedHat behaves like a typical banking trojan: when a victim opens a banking app, it creates an invisible overlay to capture login credentials and one-time passwords, giving attackers direct control over banking accounts.

What separates RedHat from other Android banking trojans is its AI-powered component. The AI assistant acts as a kind of remote set of eyes and hands for controlling the victim’s phone. Traditionally, criminals developing banking trojans must code exact coordinates for layouts, such as where a password is entered or where a login button appears. If the banking app is redesigned and changes its layout, the malware stops working. With AI, RedHat takes a picture of what is on the screen and sends it to the AI assistant, which then instructs the malware on how to proceed.

Zimperium said the tool uses AI to intelligently navigate and control the device interface in real time, making its operations more adaptable and harder for security software to detect than traditional, scripted automation. The AI assistant also appears to be independent of the malware’s operator, allowing the tool to work without requiring operators to be present in real time, according to TechRadar.

RedHat also includes advanced persistence mechanisms. It can reinstall deleted components and intercept the uninstall process, canceling removal while displaying a fake error message to the victim. TechRadar reported that there is no word so far on who the targets are or how many people might have been compromised.