Researchers Identified New AI-Driven Banking Trojan

The RedHat Android malware uses artificial intelligence to bypass security and steal user credentials.

Updated on Sept. 18, 2026 in Artificial Intelligence

Isometric editorial illustration of a complex, shifting crystalline structure composed of angular blocks, symbolizing digital security vulnerabilities.
Security researchers identified RedHat, a new Android banking trojan that uses AI to adapt to app interfaces and bypass standard security protocols. AI Illustration. Upload story photo >

Live Poll

Do you feel confident that your smartphone’s security features can protect your personal data from malware?

Security researchers have discovered a new Android banking trojan named RedHat that utilizes artificial intelligence to interpret screen layouts. This allows the malware to adapt to banking app interfaces in real-time, facilitating credential theft.

Why it matters

The integration of AI into mobile malware allows attackers to circumvent traditional defenses that rely on static interface coordinates. This adaptability means malicious software can remain effective even after developers update their banking apps.

The RedHat malware relies on Android Accessibility permissions to function and captures login data by creating invisible overlays on banking screens. It utilizes an AI component to process screenshots and navigate interface elements automatically.

The players

Zimperium zLabs

This is a mobile security research organization that tracks and documents emerging threats to smartphone operating systems.

RedHat

This is a sophisticated Android banking trojan of Chinese origin that uses artificial intelligence to automate credential theft.

The details

The malware is distributed through third-party app stores, malvertising, SMS spam, and social media channels. It features persistence mechanisms that allow it to intercept and block uninstall requests while displaying fake error messages to the user.

Timeline

  1. September 18, 2026: Zimperium zLabs published the report on the discovery of the RedHat malware.

The Tech Race

The emergence of RedHat demonstrates how advanced malware repurposes the Android Accessibility Service to automate unauthorized interactions. This signals a shift toward autonomous, AI-driven threats that replace manual coding of attack scripts with real-time visual interpretation.

Users can protect themselves by avoiding the download of applications from third-party stores or suspicious links received via SMS. Be cautious of apps requesting excessive Accessibility permissions, as these are often required to enable malicious overlay and control functions.

The takeaway

The rise of AI-enabled malware highlights the importance of keeping software updated and maintaining strict app-permission hygiene. Vigilance regarding mobile security is essential as malicious actors continue to adopt autonomous tools that can adapt to evolving interface designs.

Further reading

For more on evolving cybersecurity threats, visit our section on Artificial Intelligence.

Live Poll

Do you feel confident that your smartphone’s security features can protect your personal data from malware?