Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ai-automation (1 article)Clear

RatHat Android malware turns on wireless debugging to control phones and survive removal

Researchers at Zimperium documented RatHat, an Android banking trojan that gains deep control of a phone by abusing its own debugging tools. After tricking the user into granting accessibility permissions, it uses automated taps to enable wireless debugging, reads the on-screen pairing code, and connects to the phone's local debugging service to get shell-level access with no computer attached. It then drops components that disable security apps, open a hidden tunnel to the attacker, and restore the malware even after uninstall, intercepting the removal screen with a fake error. RatHat also uses a generative-AI engine to read the screen and navigate on its own, making it more adaptable than scripted malware.

Check
Warn users not to sideload apps from links, ads, or third-party stores, not to grant accessibility to unexpected apps, and to watch if developer options or wireless debugging turn on by themselves.
Affected
Android users who sideload apps disguised as streaming, browser, or banking software and grant accessibility; RatHat then enables wireless debugging to gain shell access, steal banking data, and persist beyond uninstallation.
Fix
Restrict sideloading and accessibility grants through mobile device management, deploy mobile threat detection, keep Google Play Protect enabled, and on infected phones expect a factory reset may be needed for full removal.