RatHat overlay-injection HTTP endpoints for credential/form exfiltration
Detects communication patterns associated with the RatHat Android banking trojan. The rule identifies a multi-stage C2 flow: first, the device fetches malicious overlay configurations (templates for spoofed login screens) and subsequently exfiltrates captured credentials or form data to the adversary's infrastructure via POST requests.
YARA-L

