Tuesday, 22 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

RatHat Android Malware Uses AI and ADB to Persist After Uninstall

Researchers warn of a new Android trojan that combines AI-driven device control with ADB-based persistence to survive uninstallation.

· 1 min read · 2 sources

Researchers have identified a new Android malware family called RatHat. Both reports describe it as using an AI-powered component to help operators remotely navigate and control infected devices. According to The Hacker News, the malware is distributed primarily through targeted campaigns.

A notable feature is its abuse of Android Debug Bridge (ADB). RatHat uses ADB to maintain shell access on the device, allowing it to remain operational even after the app is uninstalled. This persistence mechanism is highlighted in both sources.

The two reports differ slightly on attribution. The Hacker News assesses that RatHat is operated by China-based threat actors, while BleepingComputer's coverage does not specify a threat actor. The malware's AI subsystem appears designed to automate device control, helping operators manage compromised devices remotely.

Sources · 2

  1. 01RatHat Android Malware Abuses ADB to Retain Shell Access After UninstallThe Hacker News
  2. 02New RatHat Android malware uses AI to automate device controlBleepingComputer

More in Security & Privacy