RatHat Android Malware Uses AI and ADB to Persist After Uninstall
Researchers warn of a new Android trojan that combines AI-driven device control with ADB-based persistence to survive uninstallation.
Researchers have identified a new Android malware family called RatHat. Both reports describe it as using an AI-powered component to help operators remotely navigate and control infected devices. According to The Hacker News, the malware is distributed primarily through targeted campaigns.
A notable feature is its abuse of Android Debug Bridge (ADB). RatHat uses ADB to maintain shell access on the device, allowing it to remain operational even after the app is uninstalled. This persistence mechanism is highlighted in both sources.
The two reports differ slightly on attribution. The Hacker News assesses that RatHat is operated by China-based threat actors, while BleepingComputer's coverage does not specify a threat actor. The malware's AI subsystem appears designed to automate device control, helping operators manage compromised devices remotely.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.