RatHat Android malware turns on wireless debugging to control phones and survive removal
Researchers at Zimperium documented RatHat, an Android banking trojan that gains deep control of a phone by abusing its own debugging tools. After tricking the user into granting accessibility permissions, it uses automated taps to enable wireless debugging, reads the on-screen pairing code, and connects to the phone's local debugging service to get shell-level access with no computer attached. It then drops components that disable security apps, open a hidden tunnel to the attacker, and restore the malware even after uninstall, intercepting the removal screen with a fake error. RatHat also uses a generative-AI engine to read the screen and navigate on its own, making it more adaptable than scripted malware.
- Check
- Warn users not to sideload apps from links, ads, or third-party stores, not to grant accessibility to unexpected apps, and to watch if developer options or wireless debugging turn on by themselves.
- Affected
- Android users who sideload apps disguised as streaming, browser, or banking software and grant accessibility; RatHat then enables wireless debugging to gain shell access, steal banking data, and persist beyond uninstallation.
- Fix
- Restrict sideloading and accessibility grants through mobile device management, deploy mobile threat detection, keep Google Play Protect enabled, and on infected phones expect a factory reset may be needed for full removal.