Zimperium - Experts & Thought Leaders

Latest Zimperium news & announcements

Zimperium unveils RatHat: AI mobile malware insights

Zimperium, the pioneer in AI-empowered mobile security, announces that its zLabs research team has uncovered RatHat, an advanced Android malware strain linked to threat actors believed to be operating in China. RatHat uses generative AI to adaptively navigate compromised devices, steal financial credentials and maintain persistent control even after a user attempts to uninstall the malicious application. Distributed through smishing, malvertising and deceptive third-party download sites, RatHat disguises itself as a legitimate application and uses a multistage infection process to evade analysis. Once installed, it abuses Android Accessibility services to enable wireless debugging and autonomously pair with the device’s Android Debug Bridge (ADB). This allows the malware to break out of the standard application sandbox and execute commands with elevated privileges. Advanced privilege escalation Unlike conventional malware that relies primarily on predefined scripts, RatHat uses generative AI to interpret the device interface and determine how to interact with on-screen elements in real time. This makes its activity more adaptable across devices and operating environments. “RatHat represents a significant evolution in mobile malware, combining social engineering, advanced privilege escalation and AI-assisted device control within a single attack chain,” said Nico Chiaraviglio, Chief Scientist, Zimperium. “By establishing persistent access outside the application lifecycle, attackers can continue monitoring and controlling a compromised device even when the victim believes the threat has been removed.” Accessibility-based capture Zimperium researchers identified several advanced RatHat capabilities: Hardware-level credential theft: RatHat monitors raw touchscreen input to reconstruct PINs, passwords and device-unlock patterns, bypassing protections that prevent screenshots or Accessibility-based capture. Banking and payment fraud: Fraudulent overlays imitate legitimate banking, cryptocurrency and payment applications to capture login credentials and intercept one-time passcodes. AI-assisted device control: Generative AI helps the malware interpret on-screen content, locate interface elements and navigate the device dynamically. Self-restoring persistence: A hidden service operates independently of the original application, allowing RatHat to reinstall itself and restore malicious permissions after the application is removed. Persistent remote access: A concealed reverse-proxy tunnel provides attackers with an ongoing path into the device while helping communications bypass traditional network controls. Traditional application boundaries RatHat also employs multiple layers of anti-analysis and anti-debugging defenses designed to disrupt automated security tools, decompilers and malware researchers. Its architecture demonstrates how attackers are moving beyond static mobile malware toward adaptive execution chains that can operate outside traditional application boundaries. Zimperium Mobile Threat Defense (MTD) provides on-device detection against RatHat’s malicious payloads, phishing infrastructure, Accessibility abuse, privilege escalation and command-and-control activity. Zimperium Mobile Runtime Protection (zDefend) helps financial institutions, payment providers and other application owners detect overlays, screen capture, debugging services and compromised environments before credentials can be stolen.

Zimperium uncovers Mantax Otax android malware

Zimperium, the global pioneer in AI-empowered mobile security, announces that its zLabs research team has uncovered Mantax Otax, a sophisticated Android malware campaign that combines ransomware, spyware, credential theft, and remote device control in a single infection. The malware appears to target victims in Indonesia and is distributed as a standalone Android application through third-party file-sharing services, using phishing and social engineering to persuade users to sideload it. Once installed, Mantax Otax seeks device administrator and Accessibility permissions, giving attackers broad control over the compromised device. Disruptive visual overlays The malware can steal lock-screen PINs, intercept SMS messages and one-time passwords, collect contacts and call logs, access browser history, exfiltrate files and photos, capture images through the device’s cameras, and harvest WhatsApp and Telegram communications. It can also take screenshots, record and stream the screen, block applications, disable touch input, and remotely play audio or disruptive visual overlays. On devices running Android 9 and earlier, Mantax Otax can encrypt a broad range of files using a unique key retrieved from its command-and-control infrastructure, delete the originals, and replace local images with ransom notices. It then displays an on-device chat interface through which the attacker can communicate directly with the victim and demand payment. Android 10 and later limit the ransomware component’s access to files through Scoped Storage, but the malware’s surveillance, credential theft, and device-control capabilities remain a significant threat. Disrupting attacker communications “Mantax Otax shows how mobile ransomware is evolving beyond file encryption into a broader device-compromise and extortion model,” said Vishnu Pratapagiri, mobile security researcher at Zimperium zLabs. “By combining surveillance, credential theft, communications harvesting, and remote control, attackers gain multiple ways to pressure victims and exploit the sensitive data flowing through their mobile devices. This campaign reinforces why organisations need continuous, on-device protection that can detect malicious behaviour before an attacker gains control.” Zimperium Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) detect the analysed Mantax Otax samples through on-device, dynamic detection. Zimperium MTD Web Content Filtering can also block known malicious distribution sites and command-and-control traffic, helping prevent installation and disrupt attacker communications if a device is compromised. The full technical analysis, including indicators of compromise and mapped MITRE ATT&CK techniques, is available on the Zimperium blog.

Zimperium unveils AI mobile security phishing risks

Zimperium, the pioneer in AI-empowered mobile security, releases new research revealing how threat actors are using sophisticated recruitment-themed phishing campaigns to specifically target corporate credentials, with mobile devices creating an especially effective attack surface. The campaigns impersonate recruiters and HR personnel from well-known global brands, using realistic interview and scheduling experiences to lure victims into counterfeit login pages. Critically, the phishing infrastructure actively rejects personal email addresses and requires victims to enter corporate credentials, demonstrating that these attacks are intentionally designed to compromise enterprise accounts rather than indiscriminately harvest consumer credentials. Legitimate authentication windows On desktop devices, attackers can use Browser-in-the-Browser (BitB) techniques to simulate legitimate authentication windows. On mobile, the attack becomes even harder to identify. The phishing experience adapts to the smaller screen and presents victims with a full-screen counterfeit login page. With limited visibility into URLs and other browser indicators, employees can have fewer visual cues that the authentication request is fraudulent. “What makes these recruitment scams particularly concerning for enterprises is the deliberate focus on corporate identities,” said Nico Chiaraviglio at Zimperium. “Attackers are not simply looking for any credential they can steal. They are screening for enterprise accounts that can provide a path into corporate email, cloud applications and other business-critical systems. Mobile makes that deception even more effective because many of the visual signals employees rely on to recognise phishing are reduced or absent.” Impersonating prominent organisations Zimperium analysed a year of telemetry associated with brand-impersonating recruitment domains and found that the threat extends beyond the recent surge in recruitment scams. Attackers have maintained persistent infrastructure while impersonating prominent organisations across technology, retail, aviation, professional services, consumer goods and other industries. As part of its investigation, Zimperium identified 46 previously unpublished indicators of compromise (IOCs) associated with this activity. The analysis also found significant delays between the registration of impersonation domains and their identification by public threat feeds. In several cases, domains remained unreported for months or even years, creating an extended window in which employees could encounter malicious infrastructure before it appeared on traditional blocklists. Desktop-centric security controls The findings underscore a broader challenge for enterprise security teams: attacks targeting corporate identity increasingly begin on mobile devices, outside the visibility of desktop-centric security controls. Zimperium Mobile Threat Defence (MTD) dynamically analyses network activity and mobile threats directly at the device level, helping organisations identify and block credential-harvesting attacks in real time, including newly created phishing infrastructure that may not yet appear in static URL and reputation feeds.