RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
- ID
- 25858
- Status
- summarized
- Published
- 18 Sep 2026, 2:17 PM
- Fetched
- 18 Sep 2026, 2:48 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 18 Sep 2026, 2:49 PM
- Tags
- Audience
- developersai_ml_learners
What happened
Zimperium researchers disclosed RatHat, an Android malware attributed to China-based threat actors, distributed via smishing and malvertising to trick users into installing malicious APKs. It abuses Accessibility Services to enable Wireless Debugging, extracts the ADB pairing code, and self-pairs via ADB to escape the Android sandbox and persist with shell-level privileges even after the app is uninstalled. The malware also uses four anti-analysis techniques—container tampering, manifest bombs, DEX bytecode poisoning, and dual string-encryption—to evade automated analysis pipelines.
Why it matters
If you build or test Android apps that rely on ADB or Wireless Debugging, this shows a concrete attack chain where those mechanisms become a persistence vector on real devices. The anti-analysis tricks (manifest bombs, DEX poisoning) are worth knowing if you run automated APK analysis or malware pipelines, as they can crash or stall your tooling.
Discussion angle
How the ADB self-pairing escape works technically and whether Android's Wireless Debugging design needs a rethink now that malware can automate the pairing flow via Accessibility Services.