RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Ravie Lakshmanan Sep 18, 2026 Mobile Security / Malware Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline," Zimperium researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega said . "Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges." RatHat is propagated via deceptive phishing sites promoted via malvertising, smishing campaigns, and third-party forums that trick unsuspecting users into installing malware-laced APKs. These packages function as a dropper to launch the main payload, while incorporating layers of anti-analysis and anti-debug checks to sidestep detection. The four anti-analysis techniques baked into the malware are listed below - Container tampering, which declares certain files as directories in the package or sets the ZIP general-purpose encryption bit flag on some files so that they are ignored by Android's libziparchive library but not by other tools like unzip and apktool. Manifest bomb, which causes automated analysis pipelines to crash or time out by placing undocumented 0x9999 chunk headers in "AndroidManifest.xml" that's skipped by Android native runtime. DEX bytecode poisoning, which includes pseudo-instructions configured with an invalid element_width attribute so as to cause the disassembly process to fail. Dual string-encryption, which uses an encryption scheme called StringCrypto: Base64 to resist analysis. The Android malware's architecture consists of three main components: the malicious Android application, a Go agent, and an FRP reverse-proxy client. The Android app acts as a conduit to acquire critical system permissions and launch the next phase of the attack, allowing it to obtain accessibility services permissions and then abuse it to unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware is equipped to serve overlays atop specific apps to harvest credentials, record the screen using Android's MediaProjection API, intercept SMS messages, and override installation attempts by serving a fake failure overlay impersonating the Google Play Store. However, even if the victim manages to uninstall it, the attacker still retains shell access on the device. The attacker can weaponize the local service to check if the malware is installed and re-install it if not found. "The malware serializes the device's live Accessibility tree to XML and communicates with one of the world's most popular Generative AI assistants," Zimperium said. "This AI is used for non-malicious actions including: Resolving a named target's centre coordinates on the screen as JSON to direct synthetic clicks, resolving a target's actual on-screen text from the XML, [and] signaling automatic navigation commands like SCROLL_DOWN." The Go Agent executed by the APK masquerades as a native library ("liblocal-service.so") but leverages the shell access acquired via the local ADB daemon to execute commands, thereby allowing the malware to establish persistence and apply power management exemptions. The FRP client, for its part, is used to establish a secure, reverse tunnel to a command-and-control (C2) server. "The Go Agent retrieves the FRP tunnel configuration from the C2 server, enabling the FRP Client to establish a persistent, active reverse tunnel to the operator," the researchers said. "This connection is used by attackers to have access to the ADB daemon: it's a general-purpose road into the device that carries whatever the operator wants, independent of the malware's own feature set." The commands issued by the C2 server are varied as they are feature-rich, allowing the threat actors to collect SMS messages, credentials, files, lock screen PIN, pattern, or password, screen captures, keystrokes (including URLs entered in web browser address bars), and a list of installed applications. Also built into RatHat is a hardware-level keylogger that's executed by the Go Agent that's capable of recording finger presses on screen. "RatHat's multi-tiered architecture, reliance on out-of-lifecycle daemons, and use of real-time GenAI decision loops illustrate why traditional, signature-based mobile security controls are insufficient," Zimperium said. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE artificial intelligence , Malware , mobile security , Phishing ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro