ThreatPaper
Assessed, Not Confirmed

RatHat's operators are assessed to be based in China

Assessment

Zimperium's zLabs team attributes RatHat's operators to likely China-based threat actors, but the stated basis for this assessment is narrow: the prompts the malware sends to its embedded generative AI assistant are written in Mandarin. None of the reporting reviewed — including Zimperium's own quoted findings — cites supporting infrastructure analysis (hosting, registrar, IP geolocation), campaign-targeting patterns, or any other independent corroborating signal. A reader could reasonably repeat "RatHat is a Chinese malware campaign" as an established fact when it is currently a single-vendor language-based inference.

Where this claim appeared

BleepingComputer (reporting Zimperium's findings) · 2026-09-17

https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

RatHat: AI-Driven Android Malware Abuses Wireless Debugging to Steal Banking Credentials

Think this assessment is wrong? Report an error.