RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Summary

A new Android malware named RatHat, believed to be operated by Chinese threat actors, has been identified by cybersecurity researchers. RatHat employs an AI-powered system for device control and uniquely uses Android Debug Bridge (ADB) to maintain shell access even after the malware is uninstalled.

IFF Assessment

FOE

RatHat's sophisticated AI capabilities and its ability to maintain persistent access through ADB present a significant challenge for defenders.

Defender Context

Defenders should be aware of smishing and malvertising campaigns as initial infection vectors for RatHat. The malware's novel use of ADB for persistence after uninstallation is a critical evasion technique that requires advanced monitoring and detection strategies, potentially including checks for lingering ADB connections or configurations.

Read Full Story →