New Android Malware 'RatHat' Uses AI and Debug Tools to Keep Control After Uninstall
Security researchers at Zimperium have identified a sophisticated Android malware strain called RatHat, believed to be operated by China-based threat actors. The malware is notable for using an AI-powered system to navigate compromised devices and for abusing Android's Accessibility services to enable Developer Options and Wireless Debugging without the user's knowledge. This allows it to pair with Android Debug Bridge (ADB), a legitimate developer tool, to break out of the normal app sandbox and run with shell-level privileges.
RatHat spreads through smishing (SMS phishing) messages and malicious online ads that lead victims to fake download pages offering infected APK files. Once installed, these apps act as droppers that quietly deploy the main malicious payload, using several techniques designed to trick security scanners and slow down analysis by researchers. Because it establishes shell access through system-level debugging tools rather than relying solely on the app itself, RatHat can retain control of a device even if the original malicious app is uninstalled.
The malware's design, which includes a Go-based agent and a reverse-proxy component, suggests a well-resourced and technically advanced operation. Businesses that allow staff to use personal or company Android devices for work should be aware that this threat can persist beyond simple app removal, making early detection critical.