RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Zimperium researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega disclosed RatHat, a new Android malware attributed to China-based threat actors that uses an AI-powered system to navigate and control compromised devices. Distributed via smishing, malvertising, and third-party download portals, RatHat abuses Accessibility services and autonomous local ADB self-pairing to break out of the Android application sandbox and stage native daemons with shell-level privileges, retaining shell access and reinstalling itself even after the victim uninstalls the app. The malware serializes the device's live Accessibility tree to XML and communicates with a popular Generative AI assistant to resolve target coordinates and on-screen text for synthetic clicks and automatic navigation commands such as SCROLL_DOWN. Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence AI -powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing SMS/text phishing and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline,” Zimperium researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega said https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts . “Once deployed, it pairs Accessibility abuse with autonomous local ADB Android Debug Bridge self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges.” RatHat is propagated via deceptive phishing sites promoted via malvertising, smishing campaigns, and third-party forums that trick unsuspecting users into installing malware-laced APKs. These packages function as a dropper to launch the main payload, while incorporating layers of anti-analysis and anti-debug checks to sidestep detection. The four anti-analysis techniques baked into the malware are listed below – - Container tampering, which declares certain files as directories in the package or sets the ZIP general-purpose encryption bit