Close Menu
NCIJ Network NCIJ Network
    What's Hot

    French PM vows to cut public spending by €54 billion to reduce deficit

    September 18, 2026

    War may be coming. Are we psychologically ready?

    September 18, 2026

    Interview with Reuters

    September 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • French PM vows to cut public spending by €54 billion to reduce deficit
    • War may be coming. Are we psychologically ready?
    • Interview with Reuters
    • Crusoe raises $3.9B to build massive data centers and small modular ‘AI factories’
    • RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
    • Zcash miner Fortitude appoints Jaime Leverton as CEO
    • Hidden “immune organ” in the skull may help fight brain cancer
    • Australia news live: Victoria police officer charged with assault after allegedly punching and kicking handcuffed teen; embattled builders Bathla given 12-month lifeline | Australia news
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 18, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 18, 2026Mobile Security / Malware

    Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.

    “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses an automated multi-stage infection pipeline,” Zimperium researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega said.

    “Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges.”

    Cybersecurity

    RatHat is propagated via deceptive phishing sites promoted via malvertising, smishing campaigns, and third-party forums that trick unsuspecting users into installing malware-laced APKs. These packages function as a dropper to launch the main payload, while incorporating layers of anti-analysis and anti-debug checks to sidestep detection.

    The four anti-analysis techniques baked into the malware are listed below –

    • Container tampering, which declares certain files as directories in the package or sets the ZIP general-purpose encryption bit flag on some files so that they are ignored by Android’s libziparchive library but not by other tools like unzip and apktool.

    • Manifest bomb, which causes automated analysis pipelines to crash or time out by placing undocumented 0x9999 chunk headers in “AndroidManifest.xml” that’s skipped by Android native runtime.

    • DEX bytecode poisoning, which includes pseudo-instructions configured with an invalid element_width attribute so as to cause the disassembly process to fail.

    • Dual string-encryption, which uses an encryption scheme called StringCrypto: Base64 to resist analysis.

    The Android malware’s architecture consists of three main components: the malicious Android application, a Go agent, and an FRP reverse-proxy client. The Android app acts as a conduit to acquire critical system permissions and launch the next phase of the attack, allowing it to obtain accessibility services permissions and then abuse it to unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code.

    The malware is equipped to serve overlays atop specific apps to harvest credentials, record the screen using Android’s MediaProjection API, intercept SMS messages, and override installation attempts by serving a fake failure overlay impersonating the Google Play Store.

    However, even if the victim manages to uninstall it, the attacker still retains shell access on the device. The attacker can weaponize the local service to check if the malware is installed and re-install it if not found.

    “The malware serializes the device’s live Accessibility tree to XML and communicates with one of the world’s most popular Generative AI assistants,” Zimperium said. “This AI is used for non-malicious actions including: Resolving a named target’s centre coordinates on the screen as JSON to direct synthetic clicks, resolving a target’s actual on-screen text from the XML, [and] signaling automatic navigation commands like SCROLL_DOWN.”

    The Go Agent executed by the APK masquerades as a native library (“liblocal-service.so”) but leverages the shell access acquired via the local ADB daemon to execute commands, thereby allowing the malware to establish persistence and apply power management exemptions. The FRP client, for its part, is used to establish a secure, reverse tunnel to a command-and-control (C2) server.

    Cybersecurity

    “The Go Agent retrieves the FRP tunnel configuration from the C2 server, enabling the FRP Client to establish a persistent, active reverse tunnel to the operator,” the researchers said. “This connection is used by attackers to have access to the ADB daemon: it’s a general-purpose road into the device that carries whatever the operator wants, independent of the malware’s own feature set.”

    The commands issued by the C2 server are varied as they are feature-rich, allowing the threat actors to collect SMS messages, credentials, files, lock screen PIN, pattern, or password, screen captures, keystrokes (including URLs entered in web browser address bars), and a list of installed applications. Also built into RatHat is a hardware-level keylogger that’s executed by the Go Agent that’s capable of recording finger presses on screen.

    “RatHat’s multi-tiered architecture, reliance on out-of-lifecycle daemons, and use of real-time GenAI decision loops illustrate why traditional, signature-based mobile security controls are insufficient,” Zimperium said.

    Abuses access ADB Android Malware RatHat Retain Shell Uninstall
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

    US takes down NightmareStresser DDoS-for-hire platform

    Black Hat USA 2026 | OpenAI Discusses the Hugging Face Incident

    Windows 11 24H2 Home and Pro reach end of support in October

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    French PM vows to cut public spending by €54 billion to reduce deficit

    September 18, 2026

    War may be coming. Are we psychologically ready?

    September 18, 2026

    Interview with Reuters

    September 18, 2026

    Crusoe raises $3.9B to build massive data centers and small modular ‘AI factories’

    September 18, 2026
    Latest Posts

    ADNOC, SLB roll out AI-powered tool across over 120 rigs to enhance drilling ops

    August 4, 2026

    Mining threat persists in Raja Ampat, Indonesia’s ‘Amazon of the Seas’

    August 4, 2026

    Smoke Streams Across Eastern Washington

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    French PM vows to cut public spending by €54 billion to reduce deficit

    September 18, 2026

    War may be coming. Are we psychologically ready?

    September 18, 2026

    Interview with Reuters

    September 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.