importantSYS.SOURCE: The Hacker News• 2026-09-18T11:47:25+05:30
RatHat Android Malware Exploits ADB for Post-Uninstall Persistence
RatHat Android malware uses ADB exploitation to maintain shell access even after uninstallation, leveraging AI for navigation and control. It employs advanced persistence techniques, including native daemons and reverse proxies, to evade detection and enable remote command execution.
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.
"Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
*** END OF TRANSMISSION ***