Learn
active
RatHat Android malware uses AI subsystem to automate device control
- Engineer — Skip
- SOC/IR — Learn: No IOCs or mapped TTPs are available yet, so there is nothing actionable to hunt or detect today, but the AI-assisted navigation capability is a novel operator-aid technique worth tracking as similar features may appear in future mobile threat tooling.
- Leader — Learn: AI-augmented malware lowering the skill floor for remote device control is an emerging trend worth noting in mobile risk discussions, though no enterprise-targeted campaign or signals are reported here.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.