Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process.
What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script.
The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan.
It also abuses Android Debug Bridge (ADB), a legitimate tool that lets a computer communicate with an Android device. By turning on Wireless Debugging, RatHat can escape the normal app sandbox.
The attack
The infection chain is unusually elaborate for a mobile threat, combining social engineering, accessibility abuse, and remote AI decision-making into a single pipeline.
- Victims are lured through smishing (SMS phishing) texts and malicious ads that lead to fake download pages, sometimes disguised as a popular streaming app or even a browser like Chrome. These pages trick people into sideloading a malicious APK (Android Package Kit).
- Once installed, the app pressures the user into enabling Android’s Accessibility Service, using a fake “network restriction” excuse or bogus financial incentive. Accessibility services run in the background and can inspect screen content and interact with apps on the user’s behalf.
- With accessibility access, the malware silently taps through Developer Options, turns on Wireless Debugging, and reads the six-digit pairing code straight off the screen. It then pairs with the infected device without a person or computer to complete the process. This is a known, legitimate Android feature (normally used by app developers to test on a phone over Wi-Fi) that RatHat repurposes for self-escalation.
- That self-pairing gives the malware a shell-level ADB session, which it uses to drop two disguised native binaries: A Go-based “agent” that runs system commands with elevated privileges, and a reverse-proxy client that opens a persistent tunnel back to the attacker’s server, bypassing firewalls and NAT (Network Address Translation).
- To steal login credentials, the Trojan creates overlays for targeted apps, most of which are financial. These overlays can also steal one-time passwords (OTPs) and multi-factor authentication (MFA) codes.
- Perhaps its most novel capability records raw touch coordinates (where the finger touches the screen) directly from the input driver. It then matches those coordinates against a database of known keypad and pattern-lock layouts to reconstruct PIN codes and unlock patterns, completely bypassing protections against screen-reading.
Other capabilities include intercepting SMS messages, a form of semi-autonomous device control provided by the AI service, and the ability to restore the malicious app after it has been uninstalled using a hidden background program.
How to stay safe
Most of RatHat’s tricks depend on convincing someone to sideload an app and grant it accessibility permissions, which means the usual mobile security advice remains the strongest defense.
- Only install apps from Google Play or another trusted official store. This does not guarantee safety, but it significantly reduces the risk.
- Be suspicious of any app that asks you to enable Accessibility Service for reasons unrelated to accessibility. Consider Android’s Advanced Protection Mode, which Google has started using to restrict which apps can request accessibility permissions in the first place.
- Never enable Developer Options or Wireless Debugging unless you understand why you need them. Legitimate apps have no reason to ask for them.
- Use an up-to-date, real-time anti-malware solution for your device. Malwarebytes for Android detects RatHat as Android/Trojan.Exploit.RatHat.
If your device is infected with RatHat, you will need to perform a factory reset because its persistence mechanism can survive normal app removal.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.