你的 Android 手机可能保存着远超你想象的敏感信息。银行应用、密码和安全验证码都可能经过你手中这块小小的屏幕。一种新曝光的 Android 威胁“RatHat”意图获取其中的所有数据。
Your Android phone probably holds far more sensitive information than you realize. Banking apps, passwords and security codes can all pass through that little screen in your hand. A newly uncovered Android threat called RatHat wants access to all of it.
Zimperium 的安全研究人员发现了这款将生成式人工智能用于攻击的恶意软件,并发现它能把你授予的权限转化为对手机出奇深入的控制。RatHat 可以窃取银行登录凭据、拦截身份验证验证码,甚至根据你的手指触碰屏幕的位置还原 PIN 码或解锁图案。它还可以建立持久连接,即使你卸载了恶意软件,该连接仍可能继续存在。
Security researchers at Zimperium discovered the malware, which uses generative AI as part of its attack, and found that it can turn permissions you approve into surprisingly deep control of your phone. RatHat can steal banking credentials, intercept authentication codes and even reconstruct a PIN or unlock pattern from where your finger touches the screen. It can also create a persistent connection that may survive after you remove the malicious app.
这种攻击仍需手机持有者配合。RatHat 在很大程度上依赖于诱骗人们安装恶意 Android 应用,并批准授予高权限。这给了你多个机会,可以在恶意软件控制手机之前将其阻止。
The attack still needs help from the person holding the phone. RatHat relies heavily on tricking someone into installing a malicious Android app and approving powerful permissions. That gives you several opportunities to stop it before the malware takes over.
错过了 CyberGuy LIVE?观看回放,了解人工智能如何通过 5 种方式帮助你获得更好的医疗服务。
Missed CyberGuy LIVE? Watch the replay and discover 5 ways AI can help you get better healthcare.
我们的免费 CyberGuy LIVE 课程《借助人工智能改善医疗健康》已经结束,但你仍然可以观看完整回放。Kurt“CyberGuy”Knutsson 将为你讲解人工智能改善医疗健康的五种实用方法:帮助你整理健康史、记住重要的预约信息、理解复杂的医疗信息、查询处方药物,并为医生准备更明智的问题。无需任何技术经验。AI 恶意软件能够自我改写,从而逃避检测RatHat 最初利用社会工程手段。
Our free CyberGuy LIVE class Get Better Healthcare With AI has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed. AI MALWARE CAN REWRITE ITSELF TO EVADE DETECTION RatHat starts with social engineering.
Zimperium 表示,攻击者主要通过短信钓鱼、恶意广告和欺骗性的第三方下载站点传播这款恶意软件。这个恶意 APK 可能伪装成熟悉的软件,包括流媒体应用或 Chrome。熟悉的名称可能降低你的警惕。下载页面可能看起来足够逼真,让你以为自己在安装普通应用。然而,RatHat 依赖于用户在 Google Play 之外手动安装 APK。
Zimperium says attackers primarily spread it through SMS phishing, malicious advertising and deceptive third-party download sites. The malicious APK may pose as familiar software, including a streaming app or Chrome. That familiar name can lower your guard. A download page might look convincing enough to make you think you are installing a normal app. However, RatHat relies on you manually installing an APK outside Google Play.
安装后,该恶意应用会催促你启用 Android 的无障碍服务。借口可能因地区而异。在某些情况下,恶意软件会声称该权限可以解决网络问题或解锁财务收益。无障碍服务在 Android 上执行重要的合法功能。但它们也可能让获得批准的应用查看屏幕上显示的内容并与界面交互。RatHat 利用这种权限,在你无需亲自操作的情况下开始更改设置。
Once installed, the malicious app pushes you to enable Android's Accessibility Service. The excuse can vary by region. In some cases, the malware claims the permission will solve a network problem or unlock a financial benefit. Accessibility services perform important legitimate functions on Android. However, they can also give an approved app the ability to inspect what appears on your screen and interact with the interface. RatHat takes advantage of that power to begin changing settings without you doing the work yourself.
一旦 RatHat 获得无障碍权限,它就可以在 Android 设置中逐项操作,启用“开发者选项”和“无线调试”。随后,它能读取手机上显示的六位数 ADB 配对码,并直接连接到设备自身的 Android 调试桥,无需另用一台计算机完成连接。ADB 是 Android 调试桥的简称,为开发者提供强大的工具,用于测试和管理 Android 设备。
Once RatHat gets Accessibility access, it can tap through Android settings to enable Developer Options and Wireless Debugging. It can then read the six-digit ADB pairing code displayed on the phone and connect to the device's own Android Debug Bridge. No separate computer has to complete the connection. ADB, short for Android Debug Bridge, gives developers powerful tools to test and manage Android devices.
RatHat 滥用这一合法功能,在正常 Android 应用沙箱之外建立 Shell 级别访问权限。此后,该恶意软件会启动一个基于 Go 的代理程序,用于执行系统命令。它还会启动一个反向代理客户端,建立一条回连至攻击者的持久连接。Zimperium 表示,这条连接可使操作人员持续访问手机的 ADB 服务。RatHat 还将人工智能引入这一过程。
RatHat abuses that legitimate feature to establish shell-level access outside the normal Android app sandbox. From there, the malware launches a Go-based agent that can execute system commands. It also starts a reverse-proxy client that creates a persistent connection back to the attacker. Zimperium says that connection can give an operator continued access to the phone's ADB service. RatHat also brings AI into the process.
该恶意软件会把 Android 实时无障碍树中的信息发送给生成式人工智能助手。人工智能可以帮助判断某个项目在屏幕上的位置、读取屏幕上显示的文本,并告诉恶意软件何时滚动屏幕。这使该攻击比每次都遵循相同固定流程的自动化操作更具适应性。我们最近发现另一种 Android 威胁也以类似方式滥用无线调试。RatHat 则在此基础上加入了人工智能辅助导航和另一种持久化机制。
The malware sends information from Android's live Accessibility tree to a generative AI assistant. The AI can help determine where an item appears on the screen, read displayed text and tell the malware when to scroll. That makes the attack more adaptable than automation that follows the same fixed sequence every time. We recently saw another Android threat abuse Wireless Debugging in a similar way. RatHat adds AI-assisted navigation and another persistence mechanism to the mix.
获取访问权限后,RatHat可以监视金融类应用,并在正规应用界面上叠加伪造界面。这些覆盖层会诱骗用户在攻击者控制的页面中直接输入银行账户凭据。Zimperium发现,RatHat的目标包括银行和加密货币应用。该恶意软件还专门识别针对微信和支付宝等支付服务的覆盖界面。它还可以拦截短信和通知内容,为攻击者提供另一种获取一次性密码和双因素认证码的手段。
After gaining access, RatHat can watch for financial apps and display fake screens over legitimate ones. Those overlays can trick you into entering banking credentials directly into a page controlled by the attacker. Zimperium found RatHat targeting banking and cryptocurrency apps. It also specifically identified overlays aimed at payment services such as WeChat and Alipay. The malware can intercept SMS messages and notification content as well, giving attackers another way to capture one-time passwords and two-factor authentication codes.
RatHat甚至还能监视用户手指的操作。该恶意软件可以记录原始触控坐标,并将其与已知键盘布局进行比对,从而根据点击位置还原PIN码。它也可以利用类似方法恢复Android图案锁的解锁顺序。由于该恶意软件会在底层读取触控坐标,通常用于防止屏幕阅读器读取PIN数字的保护措施也无法阻止这种攻击。这意味着,犯罪分子可能根本不需要看到以文本形式显示的PIN码,用户的手指动作就可能将其泄露。
Then there is the way RatHat watches your fingers. The malware can monitor raw touch coordinates and compare those locations with known keypad layouts. That allows it to reconstruct PINs from where you tap. It can use a similar method to recover Android pattern-lock sequences. Because the malware reads those touch coordinates at a low level, protections that normally hide PIN digits from screen readers do not stop this technique. That means a criminal may never need to see your PIN displayed as text. Your finger movements can give it away.
RatHat还会设法让用户更难摆脱被入侵的手机。Zimperium发现,当用户尝试卸载恶意应用时,该恶意软件可能会进行干扰。它可以取消真正的卸载流程,并在屏幕上显示伪造的Google Play错误信息。即使用户成功卸载了眼前可见的应用,另一个问题仍然存在。RatHat会在正常的应用生命周期之外启动一个独立的原生服务。
RatHat also tries to make leaving your phone much harder than getting onto it. Zimperium found that the malware can interfere when you try to uninstall the malicious app. It can cancel the real uninstall process and place a fake Google Play error message on top of the screen. Even if you successfully remove the visible app, another problem remains. RatHat launches a separate native service outside the normal app life cycle.
即使原始应用已经消失,该服务仍可继续运行,随后重新安装恶意软件并恢复其权限。Zimperium还发现,RatHat可以请求设备管理员权限。这些权限赋予其更多控制能力,包括在有人尝试卸载时抹除设备。因此,一旦RatHat完全控制手机,这种持久驻留机制便意味着仅删除可疑应用可能并不足以解决问题。
That service can stay behind after the original app disappears. It can then reinstall the malware and restore its permissions. Zimperium also found that RatHat can request Device Admin rights. Those rights give it additional control, including the ability to wipe the device if someone tries to uninstall it. That persistence is why deleting a suspicious app may not be enough once RatHat fully compromises a phone.
Google回应CyberGuy称,根据目前的检测结果,尚未在Google Play上发现RatHat。该公司还表示,Android用户已经可通过Google Play Protect防范该恶意软件的已知版本。一位谷歌发言人告诉CyberGuy:“根据我们目前的检测结果,Google Play上未发现包含这款恶意软件的应用。在运行Google Play服务的Android设备上,Google Play Protect默认开启,可自动保护Android用户免受这款恶意软件已知版本的侵害。”
Google responded to CyberGuy and says it has not found RatHat on Google Play based on its current detection. The company also says Android users already have protection against known versions of the malware through Google Play Protect. "Based on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services," a Google spokesperson told CyberGuy.
对于通过Google Play下载应用的人来说,这无疑让人安心。这也再次说明 why keeping Play Protect enabled can add an important layer of defense if a harmful app reaches your phone from another source. RatHat在获得多个层级的访问权限后才变得危险。幸运的是,你可以在多个环节切断这条链。这些措施可以降低风险,并帮助你在问题已经发生时作出应对。
That is reassuring for people who download their apps through Google Play. It also reinforces why keeping Play Protect enabled can add an important layer of defense if a harmful app reaches your phone from another source. RatHat becomes dangerous after it gains several layers of access. Fortunately, you can break that chain at several points. These steps can reduce your risk and help you respond if something has already gone wrong.
研究人员发现:黑客劫持已验证的流媒体账户以传播恶意软件。不要安装通过短信、在线广告或不熟悉的网站收到的APK文件。RatHat很大程度上依赖诱骗人们侧载恶意应用。如果某个页面看起来像Google Play,但你能看到浏览器的地址栏,那么它仍然只是一个网站。请关闭该页面,并打开真正的Google Play商店应用。对于任何要求你重新安装Chrome或手机中已有应用的消息,也要提高警惕。请自行打开Google Play,并在那里查看该应用。
HACKERS HIJACK VERIFIED STREAMING ACCOUNT TO SPREAD MALWARE, RESEARCHERS FIND Avoid installing APK files that arrive through text messages, online ads or unfamiliar websites. RatHat relies heavily on persuading people to sideload malicious apps. If a page looks like Google Play but you can see a browser address bar, you are still on a website. Close it and open the actual Google Play Store app. Also question any message that tells you to reinstall Chrome or another app already on your phone. Open Google Play yourself and check the app there instead.
无障碍访问权限在 RatHat 的攻击中起着核心作用。因此,如果突然收到访问该权限的请求,应将其视为严重警告。打开“设置”并搜索“无障碍”。查看拥有无障碍访问权限的应用,并删除任何你不认识或已不再使用的应用的相关权限。不同 Android 手机的菜单名称可能有所不同。如果某个流媒体应用、浏览器更新或其他无关应用突然提示需要无障碍访问权限,请勿批准,除非你完全清楚其原因。
Accessibility access plays a central role in RatHat's attack. Therefore, treat an unexpected request for that permission as a serious warning. Open Settings and search for Accessibility. Review apps with Accessibility access and remove permission from anything you do not recognize or no longer use. Menu names can vary by Android phone. If a streaming app, browser update or other unrelated app suddenly tells you that Accessibility access is required, do not approve it until you know exactly why.
绝大多数 Android 用户根本不需要使用“无线调试”。RatHat 会利用该功能建立功能强大的 ADB shell 连接。打开“设置”并搜索“开发者选项”或“无线调试”。除非你有明确的使用需求,否则请保持“无线调试”关闭。如果你发现“开发者选项”或“无线调试”已启用,但不记得自己曾将其打开,请进一步检查手机上的应用和安全设置。
Most Android users never need Wireless Debugging. RatHat uses it to establish its powerful ADB shell connection. Open Settings and search for Developer options or Wireless debugging. Leave Wireless Debugging turned off unless you have a specific reason to use it. If you discover Developer Options or Wireless Debugging enabled and you do not remember turning them on, take a closer look at the apps and security settings on your phone.
安装强大的杀毒软件,并保持实时保护处于开启状态。安全软件可以帮助你在恶意应用或可疑活动进一步获取手机访问权限之前将其检测出来。前往 CyberGuy.com,查看我为 Windows、Mac、Android 和 iOS 设备评选的 2026 年最佳杀毒防护产品。
Install strong antivirus software and keep real-time protection enabled. Security software can help detect malicious apps and suspicious activity before they get deeper access to your phone. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
然而,检测到 RatHat 与彻底将其清除是两件不同的事。因为该恶意软件在表面上的应用被删除后,仍可能留下持久运行的服务,所以如果安全扫描确认 RatHat 已彻底感染你的手机,我们建议恢复出厂设置。
However, detecting RatHat and completely removing it are two different things. Because the malware can leave behind a persistent service after the visible app is removed, we recommend a factory reset if a security scan confirms RatHat has fully infected your phone.
Google 表示,通过默认启用的 Google Play 保护,安装了 Google Play 服务的 Android 设备可自动抵御已知版本的 RatHat。你仍可检查该功能是否已开启。打开 Google Play 商店 > 点击个人资料头像 > Play 保护 > 设置。确保“使用 Play 保护扫描应用”已开启。你还可以启用“改进有害应用检测”。此功能会向 Google 提供更多有关从 Google Play 以外来源安装的陌生应用的信息,以便检查这些应用是否存在有害行为。
Google says Android users are automatically protected against known versions of RatHat through Google Play Protect, which comes turned on by default on Android devices with Google Play Services. You can still check that it is enabled. Open the Google Play Store > tap your profile picture > Play Protect > Settings. Make sure Scan apps with Play Protect is turned on. You can also enable Improve harmful app detection. This gives Google additional information about unfamiliar apps installed outside Google Play so they can be checked for harmful behavior.
Android 的“高级保护”可在受支持的设备上提供另一层有效防护。Google 表示,它会阻止安装来自未知来源的应用,并将无障碍服务限制为经过验证的无障碍工具。在“设备保护”处于启用状态时,它还会防止有人关闭 Play 保护。要开启该功能,请打开设置 > 安全和隐私 > 高级保护 > 开启“设备保护”。Google 提醒,手机可能需要重启。
Android's Advanced Protection can provide another useful barrier on supported devices. Google says it blocks app installations from unknown sources and restricts Accessibility services to verified accessibility tools. It also prevents Play Protect from being turned off while Device protection is active. To turn it on, open Settings > Security & privacy > Advanced Protection > turn on Device protection. Google notes that your phone may need to restart.
对于很少安装非官方渠道应用的人来说,这些额外限制可以封堵 RatHat 依赖的两条攻击途径。数千个遭入侵网站诱骗你安装恶意软件请在 Android 安全更新和应用更新推出后及时安装。更新可修复已知漏洞,并加强整台手机的防护。已有记录的 RatHat 感染链主要依赖恶意下载和滥用权限,因此仅更新 Android 系统无法解决这一问题。即便如此,及时使用最新软件仍可堵住攻击者可能试图利用的其他安全漏洞。
For someone who rarely sideloads apps, those extra restrictions can remove two of the avenues RatHat relies on. THOUSANDS OF HACKED SITES TRICK YOU INTO INSTALLING MALWARE Install Android security updates and app updates when they become available. Updates fix known vulnerabilities and strengthen protections across your phone. RatHat's documented infection chain depends primarily on malicious downloads and permission abuse, so an Android update alone will not solve the problem. Even so, running current software closes other security gaps that attackers could try to exploit.
RatHat部分通过Smashing传播,Smashing是通过短信发送的网络钓鱼。紧急消息可能会在您停下来质疑之前将您推向恶意下载。避免点击意外短信中的链接,这些短信告诉您安装应用程序或修复手机上的问题。相反,请打开公司的官方应用程序或亲自访问其已知网站。同样的建议适用于提供应用程序的在线广告。恶意广告可能会导致令人信服的下载页面,这些页面与它们所代表的公司无关。
RatHat spreads partly through smishing, which is phishing delivered by text message. An urgent message can push you toward a malicious download before you stop to question it. Avoid tapping links in unexpected texts that tell you to install an app or fix a problem on your phone. Instead, open the company's official app or visit its known website yourself. The same advice applies to online ads offering apps. Malvertising can lead to convincing download pages that have nothing to do with the company they appear to represent.
如果防病毒软件标记了RatHat,或者您有充分的理由认为您的手机已被入侵,请停止在手机上输入密码和财务信息。使用另一个受信任的设备更改重要密码。从您的主电子邮件帐户开始,因为访问电子邮件可以帮助攻击者重置其他帐户。然后检查你的银行和信用卡帐户的活动,你不承认。如果您发现任何可疑情况,请使用卡背面的号码或通过其官方应用程序联系金融机构。
If antivirus software flags RatHat or you have strong reason to think your phone has been compromised, stop entering passwords and financial information on it. Use another trusted device to change important passwords. Start with your primary email account, since access to email can help an attacker reset other accounts. Then check your bank and credit card accounts for activity you do not recognize. If you spot anything suspicious, contact the financial institution using the number on the back of your card or through its official app.
如果RatHat得到确认,我们建议出厂重置,而不是依赖于正常卸载。RatHat的单独后台组件可以在可见恶意应用程序消失后继续存在。在重置手机之前,请保存您知道安全的个人照片或文件。重置后,通过Google Play再次安装应用程序。避免从旧备份重新安装不熟悉的APK文件。在返回重置电话上的敏感帐户之前,您还应该更改另一个受信任设备的凭据。
If RatHat is confirmed, we recommend a factory reset rather than relying on a normal uninstall. RatHat's separate background component can survive after the visible malicious app disappears. Before resetting the phone, preserve personal photos or documents you know are safe. After the reset, install apps again through Google Play. Avoid reinstalling unfamiliar APK files from an old backup. You should also change credentials from another trusted device before returning to sensitive accounts on the reset phone.
RatHat 会针对银行账户凭据和验证码,因此清理手机后不能就此结束。您应继续核查银行对账单和安全通知,同时留意并非由您发起的密码重置消息或身份验证请求。如果您认为除登录凭据外的个人信息也可能已经泄露,可以考虑使用身份盗窃防护服务来监测可疑活动。迅速采取行动,可以减少被盗信息日后被利用所造成的损害。
RatHat can target banking credentials and authentication codes, so cleaning the phone should not be the end of your response. Continue reviewing bank statements and alerts. Also watch for password-reset messages or authentication requests you did not initiate. If you believe personal information beyond your credentials may have been exposed, consider an identity theft protection service that can help monitor for suspicious activity. Acting quickly can limit the damage if stolen information gets used later.
AI 组件的加入让 RatHat 显得与众不同,但这种攻击仍始于一个非常熟悉的方式:诱骗人们信任恶意下载,并批准一项高风险权限。这让 Android 用户有机会在 RatHat 发展到破坏性最大的阶段之前将其阻止。谷歌的回应也提供了另一项重要的安心感。该公司表示,根据其检测结果,目前 Google Play 上尚未发现包含 RatHat 的应用,而且 Play Protect 已经可以保护 Android 用户免受已知版本这一恶意软件的侵害。
The AI component makes RatHat unusual, but the attack still begins with something very familiar: getting someone to trust the wrong download and approve a powerful permission. That gives Android users a chance to stop RatHat before it reaches the most damaging stages. Google's response adds another important piece of reassurance. The company says no apps containing RatHat are currently showing up on Google Play based on its detection, and Play Protect already guards Android users against known versions of the malware.
尽管如此,只有避免侧载可疑应用并密切留意高权限请求,这种保护才能发挥最大作用。请保持 Play Protect 处于开启状态,并为手机加装强大的防病毒保护。除非您完全清楚为何需要无线调试,否则应将其关闭。如果 RatHat 确实被安装到设备上,不要以为删除应用就能解决问题。一旦确认感染,就需要进行更加全面、严格的清理。
Still, that protection works best when you avoid sideloading questionable apps and pay close attention to powerful permission requests. Keep Play Protect running and add strong antivirus protection to your phone. Wireless Debugging should stay off unless you know exactly why you need it. If RatHat does make it onto a device, do not assume deleting the app solves the problem. A confirmed infection calls for a much more serious cleanup.
得知 RatHat 这类由 AI 驱动的恶意软件可以悄无声息地控制您的手机,是否会让您在安装 Google Play 之外的应用时更加谨慎?请通过 CyberGuy.com 写信与我们联系。注册我的免费《CyberGuy 报告》
Does knowing AI-powered malware like RatHat can quietly take control of your phone make you think twice about installing apps outside Google Play? Let us know by writing to us at CyberGuy.com. Sign up for my FREE CyberGuy Report