RatHat Android RAT Uses ADB and AI to Steal Credentials and Resist Removal
Security researchers at Zimperium zLabs have identified a critical Android malware called RatHat that tricks users into enabling accessibility features to hijack the device's own Android Debug Bridge interface. Once installed via phishing SMS, malicious ads, or third-party download links, the dropper extracts a payload that silently enables wireless debugging and pairs with the device locally without any external PC. The malware then deploys a persistent Go-based shell agent and an FRP reverse proxy client, allowing attackers to execute OS commands remotely and maintain an external communication channel through mobile networks. RatHat can steal financial credentials and one-time passwords, overlay fake screens on banking apps, and automatically reinstall itself even after the user removes the main application. The malware's self-recovery and mutual monitoring design make it particularly difficult to eradicate without specialized intervention.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in