Cybersecurity researchers have identified a new Android malware named RatHat that uses advanced techniques to maintain access to compromised devices even after users attempt to uninstall the malicious application. Researchers have assessed that the malware is operated by China-based threat actors and uses artificial intelligence capabilities to navigate and control infected devices. According to researchers from Zimperium, RatHat is distributed mainly through targeted smishing campaigns, malvertising activities, and deceptive third-party download portals that trick users into installing malicious Android application packages (APKs). The malware uses a multi-stage infection process that combines accessibility service abuse with Android Debug Bridge (ADB) techniques to bypass standard application restrictions and establish deeper control over affected devices.
RatHat relies on deceptive websites, phishing messages, and unofficial forums to spread malware-laced APK files. Once installed, the application works as a dropper that launches additional malicious components while using multiple anti-analysis methods to avoid detection. Researchers identified several techniques used by RatHat to complicate security analysis, including container tampering, which manipulates package structures to interfere with analysis tools, and a manifest-based technique designed to disrupt automated inspection systems. The malware also uses DEX bytecode poisoning to create difficulties during reverse engineering and applies dual string encryption through a method called StringCrypto: Base64 to make its internal operations harder to analyze. These capabilities allow RatHat to remain more difficult to detect through traditional security mechanisms.
The malware architecture consists of three primary components: a malicious Android application, a Go-based Agent, and an FRP reverse-proxy client. The Android application initially attempts to obtain important permissions, including accessibility service access, which is then abused to enable Developer Options, activate Wireless Debugging, and retrieve the six-digit ADB pairing code. Through this process, RatHat can create a local ADB connection and execute commands with shell-level privileges. Researchers noted that even if users remove the original malicious application, attackers may still retain access through the local service created by the malware. The attacker-controlled service can check whether RatHat remains installed and attempt to restore the malware if it is removed from the device.
RatHat is also capable of collecting sensitive information from infected devices. The malware can display overlays over selected applications to capture credentials, record screens using Android’s MediaProjection API, intercept SMS messages, and present fake Google Play Store failure messages to interfere with installation attempts. The Go Agent, which disguises itself as a native library named “liblocal-service.so,” uses acquired shell access to execute commands, establish persistence, and apply power management exemptions. Meanwhile, the FRP client creates a reverse tunnel to a command-and-control (C2) server, allowing attackers to maintain communication with compromised devices and issue various commands.
Researchers stated that RatHat can collect SMS messages, credentials, files, lock screen PINs, patterns, passwords, screenshots, keystrokes, browser URLs, and installed application details. The malware also includes a hardware-level keylogger operated through the Go Agent, allowing it to record touch activity on the device screen. Zimperium researchers highlighted that RatHat uses generative AI capabilities to support automated navigation by analyzing accessibility data and determining actions such as screen coordinates, text locations, and scrolling commands. The combination of AI-assisted decision making, ADB-based access, and persistent background services demonstrates the growing complexity of mobile threats and highlights the need for stronger Android security practices, including avoiding untrusted downloads, reviewing application permissions, and keeping devices updated.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.