26-09-2026
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
Report completeness: High
Threats:
Rathat
Smishing_technique
Frpc_tool
Credential_harvesting_technique
Victims:
Financial institutions, E wallets, Payment providers, Banking applications, Cryptocurrency applications, Wechat, Alipay
Industry:
Financial
Geo:
China
TTPs:
Tactics: 1
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1005, T1010, T1021, T1027, T1027.009, T1027.013, T1036, T1036.005, T1041, T1056.001, have more...
IOCs:
File: 17
Hash: 162
Url: 13
Domain: 7
Soft:
Android, apktool, QEMU, Chrome, Google Play, opera, WeChat
Algorithms:
base64, xor, zip
Links:
https://github.com/fatedier/frphttps://github.com/Zimperium/IOC/tree/master/2026-09-RatHat/