RatHat's operators are assessed to be based in China
Assessment
Zimperium's zLabs team attributes RatHat's operators to likely China-based threat actors, but the stated basis for this assessment is narrow: the prompts the malware sends to its embedded generative AI assistant are written in Mandarin. None of the reporting reviewed — including Zimperium's own quoted findings — cites supporting infrastructure analysis (hosting, registrar, IP geolocation), campaign-targeting patterns, or any other independent corroborating signal. A reader could reasonably repeat "RatHat is a Chinese malware campaign" as an established fact when it is currently a single-vendor language-based inference.
Where this claim appeared
BleepingComputer (reporting Zimperium's findings) · 2026-09-17
https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
RatHat: AI-Driven Android Malware Abuses Wireless Debugging to Steal Banking CredentialsThink this assessment is wrong? Report an error.