Back to news
Cybersecurity Alert
September 21, 2026 by EmailMeNow IT Consulting

RatHat Android Scam Steals Bank Logins and Can Learn Your Phone PIN

Zimperium’s RatHat Android Trojan uses smishing, fake overlays, and stolen OTP codes, and can reconstruct a screen lock. Audits (ideal 100%): zimperium.com 78%, malwarebytes.com 71%, google.com 55%, bankofamerica.com 53%.

Source: Zimperium zLabs · Malwarebytes

NewsPhishingAndroidBanking FraudMFAYubiKeyAuthenticator AppsCybersecurity
Android phone showing an unexpected text and an accessibility prompt, with a note not to sideload apps

Zimperium zLabs published RatHat on September 16, 2026: an Android Trojan that starts with smishing or a bad download ad, then steals bank logins, one-time codes, and — unusually — can reconstruct a lock-screen PIN or pattern from where you touch the glass. Malwarebytes recapped the same family on September 18. BleepingComputer followed on September 17.

This is not a report that Google Play, Bank of America, or a named U.S. bank was hacked. It is sideloaded malware. A hardware key on a clean computer still helps after you rebuild the phone. An authenticator on the infected handset does not.

We scanned zimperium.com, malwarebytes.com, google.com, and bankofamerica.com. 100% is the ideal overall domain-security score. None reach it.

Android phone showing an unexpected text and an accessibility prompt, with a note not to sideload apps

Snapshot

FieldDetail
ResearchersZimperium zLabs · Sept 16, 2026
RecapMalwarebytes · Sept 18
ChannelSMS / ads → fake download page → sideloaded APK
TheftBank overlays, OTP / SMS intercept, lock-screen PIN / pattern
Who is at riskAndroid users who tap unexpected links or install outside Play
If infectedFactory reset, then change bank and Google passcodes from a trusted device

What victims are talked into

Do not treat this as setup advice. This is what researchers say the lure does after someone installs a package outside Google Play.

StepWhat happens
1. LureText or ad for a “streaming app” or “Chrome” APK
2. AccessibilityFake “network restriction” or money bait to turn the service on
3. Debug abuseThe app walks Developer Options and Wireless Debugging — a real Android feature, misused so the malware can run with more privilege without a PC
4. OverlaysFake login / PIN screens over banking and payment apps (Zimperium also shows WeChat and Alipay PIN lures)
5. CodesSMS and notification listeners steal OTP / MFA codes on the phone
6. Screen lockTouch positions on the PIN pad or pattern grid are matched to known layouts

Malwarebytes’ point on the last step: Android’s usual screen-reading blocks do not stop raw touch geometry. BleepingComputer adds that uninstall can be canceled with a fake Play error, and a hidden helper can put the app back. That is why “delete the suspicious app” alone is not enough.

Zimperium says a generative-AI helper reads the on-screen layout so taps are not a fixed script. Researchers tie Chinese-language prompts to operators appearing to work from China. That is attribution language in a malware report, not a public indictment.

Fake banking overlay sitting on top of a generic phone banking screen

What to do

  1. Do not tap links in unexpected texts. Type play.google.com yourself.
  2. Banks and Google do not need you to Install unknown apps or turn on Accessibility to “unlock an account.”
  3. Leave Developer Options and Wireless Debugging off unless you know why they are on.
  4. Review Accessibility apps. Revoke anything that is not a real screen reader or similar aid.
  5. Turn on Play Protect. Google’s opt-in Advanced Protection Mode (Android 16+) can block unknown-source installs. Android 17 beta additionally restricts Accessibility for apps that are not real accessibility tools — that tightening is not on every phone yet.
  6. If you already sideloaded something: use a second device to freeze cards and change bank, Google, and email passwords. Malwarebytes: factory-reset the Android. Then set a new screen lock.

Malwarebytes names the family Android/Trojan.Exploit.RatHat. We do not publish sample links, hashes, or C2 lists.

MFA: YubiKey and Google Authenticator vs a hijacked phone

A YubiKey on a clean laptop is still the right enroll for Bank of America web login after the phone is rebuilt. It does not stop overlays and OTP theft while the RAT is on the unlocked device. Google Authenticator on that same phone can be harvested with the other codes.

GradeMeaning
FailSMS, email OTP, or no public key / open TOTP
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Bank of AmericaStrongYesNo
Google AccountStrongYesYes
Malwarebytes AccountFailNoNo

Directory: MFA support directory. BofA USB security key. Google passkeys / Authenticator. Malwarebytes Account email verification is email OTP (Fail).

Prefer the hardware key on a computer that did not install the APK. See the national banks MFA scorecard.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside an authenticator phone and a note that codes on a hijacked phone can be stolen

Independent cybersecurity audits

We audited researcher, Play-ecosystem, and a U.S. bank host named in overlay coverage on September 21, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean Play or a bank was breached.

OrganizationDomainOverallvs 100%
Zimperiumzimperium.com78%−22
Malwarebytesmalwarebytes.com71%−29
Googlegoogle.com55%−45
Bank of Americabankofamerica.com53%−47
DomainIdentityTransportWebsite
zimperium.com90%45%65%
malwarebytes.com90%45%43%
google.com50%70%37%
bankofamerica.com50%45%37%

Audit links: zimperium.com · malwarebytes.com · google.com · bankofamerica.com

Type those hosts yourself. Do not use a download link from a text.

Domain audit scoreboard versus the 100 percent ideal

Website stack

Passive homepage + Certificate Transparency probes (September 21, 2026). Versions only — not a claim these sites were compromised.

DomainStack note
zimperium.comHubSpot (vendor-managed); Sectigo TLS expires 2027-03-28
malwarebytes.comWordPress, generator version hidden; Amazon Trust TLS expires 2027-03-19
google.comCMS undetected; Google Trust Services TLS expires 2026-10-20 (~28 days); HTTP→HTTPS redirect not confirmed on probed hosts
bankofamerica.comCMS undetected; DigiCert TLS expires 2027-03-26

A short Google leaf date is a certificate calendar note, not a Play Store outage.

Blacklist and lookalikes

Email blacklist checks (public DoH, September 21, 2026): zimperium.com, malwarebytes.com, google.com, and bankofamerica.com were clear on mail/domain lists we can query.

Registered lookalikes (BEC / standard squat scan — not proof RatHat used them):

LookalikeTechniqueSignal
zimperium.appTLD swapNS + A
malewarebytes.cominsertionNS + A
geoogle.cominsertionNS + A + MX
bankofamerica.appTLD swapNS
bankoifamerica.cominsertionNS + A + MX

Zimperium already redirects several defensive TLDs (.io, .org, .net). Type zimperium.com, malwarebytes.com, google.com, and bankofamerica.com. Continuous monitoring: Cybersquat Domain Monitoring.

CourtListener RECAP searches for RatHat and Android overlay / Wireless-Debugging banking malware did not return a matching 2026 docket. This remains a research alert, not a filed U.S. case we can cite.

Sources: Zimperium zLabs — RatHat, Sept 16, 2026 · Malwarebytes, Sept 18, 2026 · BleepingComputer, Sept 17, 2026 · Android Advanced Protection Mode · Android Authority — Android 17 beta Accessibility. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 21, 2026. Domain scores: audit.emailmenow.com only. No sample hashes, lure URLs, or install commands in this post.