{"id":21637,"date":"2026-09-23T13:54:59","date_gmt":"2026-09-23T17:54:59","guid":{"rendered":"https:\/\/www.psafe.com\/en\/blog\/?p=21637"},"modified":"2026-09-23T13:56:08","modified_gmt":"2026-09-23T17:56:08","slug":"rathat-android-malware-ai-adb","status":"publish","type":"post","link":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/","title":{"rendered":"RatHat Android malware: how AI and permissions are used"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">RatHat Android malware drew attention because it uses artificial intelligence during an attack. The more useful part of the story is the path it takes through a phone. According to Zimperium&#8217;s analysis, the malicious app relies on a manual install and tries to gain access to powerful Android features, including Accessibility and Wireless Debugging. Those permissions can help it capture bank logins, PINs, and one-time codes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Public reporting does not confirm a mass campaign, Google Play distribution, or specific targeting in the United States. This article covers what researchers found, which choices allow the attack to progress, and what you can check without treating every unusual phone problem as evidence of RatHat.<\/span><\/p>\n<h2><b>What is RatHat Android malware?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">RatHat is the name Zimperium&#8217;s zLabs team gave to Android malware found in samples distributed through fake messages, malicious ads, and deceptive download pages. Zimperium published its<\/span><a href=\"https:\/\/zimperium.com\/blog\/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts\"> <span style=\"font-weight: 400;\">technical analysis of RatHat<\/span><\/a><span style=\"font-weight: 400;\"> on September 16, 2026.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Researchers found tools that imitate app screens, monitor activity, and intercept codes from text messages or notifications. RatHat also tries to keep components running after the main app is removed. Zimperium observed that behavior in the samples it studied. The report does not establish that every infection follows the same sequence or that the malware has reached a large number of people.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AI helps the malware locate screen elements and choose where to tap. It does not install the file on its own. The chain begins when someone downloads an APK outside the official store and approves access that deserves closer attention.<\/span><\/p>\n<h2><b>How does RatHat reach a phone?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The route described by Zimperium starts with social engineering. A text, ad, or webpage pretends to come from a familiar source and offers an APK file. One sample posed as a streaming service and could change its name and icon.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An APK is the file format Android uses to install apps. A file from outside the official store is not automatically malicious. Risk rises when you cannot confirm its source, the download arrives unexpectedly, or the app requests controls that make no sense for its stated purpose.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Before installing, check the developer, the web address, and the reason the app is unavailable in the store. If the offer came through a message or ad, find the service through a known route instead of the supplied link.<\/span><a href=\"https:\/\/support.google.com\/android\/answer\/2812853?hl=en\"> <span style=\"font-weight: 400;\">Google Play Protect<\/span><\/a><span style=\"font-weight: 400;\"> can also scan apps from other sources, though no security tool can promise perfect detection.<\/span><\/p>\n<h2><b>Three permissions help the attack progress<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The RatHat chain combines three decisions that appear on the Android screen.<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The user installs an APK obtained outside the store. The file opens the initial path and tries to look legitimate.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The app requests Accessibility access. Android provides this feature to help people use their devices, but malicious software can abuse it to read the screen and perform taps.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The malware tries to enable Developer options and Wireless Debugging. It then uses ADB to gain control beyond the permissions normally available to an app.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">ADB stands for Android Debug Bridge. Developers and repair technicians use it to test devices and run commands. Wireless Debugging provides that connection without a cable. Most users should leave it off when they do not need it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">RatHat uses Accessibility to move through settings, capture a pairing code, and create a local ADB connection. Its AI-assisted automation helps it find buttons and text across different interfaces. This makes the process more adaptable, but the earlier install and permissions still matter.<\/span><\/p>\n<p><b>Related:<\/b><a href=\"https:\/\/www.psafe.com\/en\/blog\/apps-using-camera-microphone-location-android\/\"> <span style=\"font-weight: 400;\">Review which apps can access sensitive Android features<\/span><\/a><\/p>\n<h2><b>Is RatHat targeting people in the US?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">As of September 22, 2026, public sources did not confirm a campaign focused on the United States, a victim count, or affected US banks. Zimperium describes global financial targeting in the samples but does not provide a country list.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That gap matters when reading headlines. RatHat documents a possible attack technique. It does not give us grounds to label every unknown APK or slow phone as a RatHat infection. The checks below still help because they reduce common risks from malicious Android apps.<\/span><\/p>\n<h2><b>Which signs deserve a closer look?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">One symptom cannot identify RatHat. Look for the surrounding context, such as a recent install from an unknown source and permissions you do not remember approving.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An unfamiliar app appears among enabled Accessibility services.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Developer options or Wireless Debugging are on without a known reason.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A sideloaded app changed its name, disappeared from the launcher, or resists removal.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">An overlay appears over a banking app or asks for a PIN or authentication code.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">You notice account access or transactions you do not recognize.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Android lets you<\/span><a href=\"https:\/\/support.google.com\/android\/answer\/9431959?hl=en\"> <span style=\"font-weight: 400;\">review permissions for installed apps<\/span><\/a><span style=\"font-weight: 400;\">. Menu names vary by phone maker and Android version. Keep legitimate Accessibility tools enabled when you recognize and use them, including screen readers and password managers.<\/span><\/p>\n<h2><b>What should you do after installing a suspicious APK?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If you only received the link, delete the message and do not install the file. If you installed the app, consider disconnecting the phone from mobile data and Wi-Fi, provided that doing so will not block an essential safety action. Use another trusted device to review sensitive accounts.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Check Accessibility, device administrator apps, and Wireless Debugging. Remove access you do not recognize. A security scan may help identify suspicious files and apps, but it does not replace reviewing affected accounts and settings.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Treat bank credentials as exposed if you entered a password, PIN, or one-time code. Use the institution&#8217;s verified app, website, help center, or official support channel from a trusted device, then review recent activity.<\/span><a href=\"https:\/\/www.identitytheft.gov\/\"> <span style=\"font-weight: 400;\">IdentityTheft.gov<\/span><\/a><span style=\"font-weight: 400;\"> provides a recovery plan for identity-related misuse.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Zimperium found a component that could remain active after the main app was uninstalled. Removing the icon may therefore be insufficient when persistent ADB access exists. Use the phone maker&#8217;s official support channel if you find concrete signs of that access. A factory reset may form part of recovery, but it requires preparation and should not follow from a vague suspicion alone.<\/span><\/p>\n<h2><b>Lower the risk before the next download<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Keep Android and your apps updated. Leave Wireless Debugging off when you do not use it, and read Accessibility requests before approving them. A video player, promotion, or routine update rarely needs to control the whole interface.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Avoid using a suspicious page to prove its own legitimacy. When a message says you need a new app, open the service&#8217;s known website or official store listing yourself. That short pause often stops the chain before an unknown file reaches the phone.<\/span><\/p>\n<h2><b>Keep reading<\/b><\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.psafe.com\/en\/blog\/how-to-check-if-a-link-is-safe\/\"><span style=\"font-weight: 400;\">How to Check If a Link Is Safe: How dfndr Scans Suspicious URLs<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.psafe.com\/en\/blog\/android-update-phone-security-2\/\"><span style=\"font-weight: 400;\">Android Security Update: Check the August Patch<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.psafe.com\/en\/blog\/phone-acting-strange-sim-card-not-the-cause\/\"><span style=\"font-weight: 400;\">Is Your Phone Acting Strange? Here&#8217;s Why the SIM Card Is Not Always the Cause<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.psafe.com\/en\/blog\/android-update-phone-security\/\"><span style=\"font-weight: 400;\">Why Updating Android Helps Protect Your Phone, Even When Nothing Looks Different<\/span><\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>RatHat Android malware drew attention because it uses artificial intelligence during an attack. The more useful part of the story is the path it takes through a phone. [&hellip;]<\/p>\n","protected":false},"author":96,"featured_media":21638,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12301,4488],"tags":[12462],"class_list":["post-21637","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exclusive-news","category-security-alerts","tag-destaques"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>RatHat Android malware: AI and permissions explained<\/title>\n<meta name=\"description\" content=\"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"RatHat Android malware: AI and permissions explained\" \/>\n<meta property=\"og:description\" content=\"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/\" \/>\n<meta property=\"og:site_name\" content=\"PSafe Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-23T17:54:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-23T17:56:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1-1024x576.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"gabriel.machado\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/\"},\"author\":{\"name\":\"gabriel.machado\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/#\\\/schema\\\/person\\\/8b2d7ff2c3fb52135e2969fa60058c2e\"},\"headline\":\"RatHat Android malware: how AI and permissions are used\",\"datePublished\":\"2026-09-23T17:54:59+00:00\",\"dateModified\":\"2026-09-23T17:56:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/\"},\"wordCount\":1141,\"image\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Banners-Blog-1.png\",\"keywords\":[\"destaques\"],\"articleSection\":[\"Exclusive News\",\"Security Alerts\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/\",\"url\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/\",\"name\":\"RatHat Android malware: AI and permissions explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Banners-Blog-1.png\",\"datePublished\":\"2026-09-23T17:54:59+00:00\",\"dateModified\":\"2026-09-23T17:56:08+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/#\\\/schema\\\/person\\\/8b2d7ff2c3fb52135e2969fa60058c2e\"},\"description\":\"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Banners-Blog-1.png\",\"contentUrl\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Banners-Blog-1.png\",\"width\":1672,\"height\":941},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/rathat-android-malware-ai-adb\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"RatHat Android malware: how AI and permissions are used\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/\",\"name\":\"PSafe Blog\",\"description\":\"Articles and news about Mobile Security, Android, Apps, Social Media and Technology in general.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/#\\\/schema\\\/person\\\/8b2d7ff2c3fb52135e2969fa60058c2e\",\"name\":\"gabriel.machado\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g\",\"caption\":\"gabriel.machado\"},\"url\":\"https:\\\/\\\/www.psafe.com\\\/en\\\/blog\\\/author\\\/gabriel-machado\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"RatHat Android malware: AI and permissions explained","description":"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/","og_locale":"en_US","og_type":"article","og_title":"RatHat Android malware: AI and permissions explained","og_description":"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.","og_url":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/","og_site_name":"PSafe Blog","article_published_time":"2026-09-23T17:54:59+00:00","article_modified_time":"2026-09-23T17:56:08+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1-1024x576.png","type":"image\/png"}],"author":"gabriel.machado","twitter_misc":{"Written by":false,"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#article","isPartOf":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/"},"author":{"name":"gabriel.machado","@id":"https:\/\/www.psafe.com\/en\/blog\/#\/schema\/person\/8b2d7ff2c3fb52135e2969fa60058c2e"},"headline":"RatHat Android malware: how AI and permissions are used","datePublished":"2026-09-23T17:54:59+00:00","dateModified":"2026-09-23T17:56:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/"},"wordCount":1141,"image":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#primaryimage"},"thumbnailUrl":"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1.png","keywords":["destaques"],"articleSection":["Exclusive News","Security Alerts"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/","url":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/","name":"RatHat Android malware: AI and permissions explained","isPartOf":{"@id":"https:\/\/www.psafe.com\/en\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#primaryimage"},"image":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#primaryimage"},"thumbnailUrl":"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1.png","datePublished":"2026-09-23T17:54:59+00:00","dateModified":"2026-09-23T17:56:08+00:00","author":{"@id":"https:\/\/www.psafe.com\/en\/blog\/#\/schema\/person\/8b2d7ff2c3fb52135e2969fa60058c2e"},"description":"Learn how RatHat Android malware uses AI, Accessibility and ADB, what remains unconfirmed in the US, and what to do after a suspicious install.","breadcrumb":{"@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#primaryimage","url":"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1.png","contentUrl":"https:\/\/www.psafe.com\/en\/blog\/wp-content\/uploads\/2026\/09\/Banners-Blog-1.png","width":1672,"height":941},{"@type":"BreadcrumbList","@id":"https:\/\/www.psafe.com\/en\/blog\/rathat-android-malware-ai-adb\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/www.psafe.com\/en\/blog\/"},{"@type":"ListItem","position":2,"name":"RatHat Android malware: how AI and permissions are used"}]},{"@type":"WebSite","@id":"https:\/\/www.psafe.com\/en\/blog\/#website","url":"https:\/\/www.psafe.com\/en\/blog\/","name":"PSafe Blog","description":"Articles and news about Mobile Security, Android, Apps, Social Media and Technology in general.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.psafe.com\/en\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.psafe.com\/en\/blog\/#\/schema\/person\/8b2d7ff2c3fb52135e2969fa60058c2e","name":"gabriel.machado","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8ef66f9f6a08c14e2eb1ef80d675f95dcc3435b424502b92a6bc1e87740c0658?s=96&d=mm&r=g","caption":"gabriel.machado"},"url":"https:\/\/www.psafe.com\/en\/blog\/author\/gabriel-machado\/"}]}},"_links":{"self":[{"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/posts\/21637","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/users\/96"}],"replies":[{"embeddable":true,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/comments?post=21637"}],"version-history":[{"count":1,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/posts\/21637\/revisions"}],"predecessor-version":[{"id":21639,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/posts\/21637\/revisions\/21639"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/media\/21638"}],"wp:attachment":[{"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/media?parent=21637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/categories?post=21637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.psafe.com\/en\/blog\/wp-json\/wp\/v2\/tags?post=21637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}