Cyber Threat Intel 5 min read

Uninstall RatHat and It Reinstalls Itself

A new Android malware family escapes the app sandbox by switching on wireless debugging and pairing with the phone as a developer would. Removing it leaves the attacker.

Priya Nair
Data, AI Governance & Policy Analyst
Published 23 Sep 2026, 9:08 AM (SGT)
Share:
A hand holding a smartphone in the dark with a messaging app open on screen A hand holding a smartphone in the dark with a messaging app open on screen Photo by RDNE Stock project on Pexels
Advertisement

23 SEP 2026 — RatHat is a new Android malware family that talks to a commercial AI assistant to work out where to tap. The AI part gets the attention, but the part that should worry anyone is simpler: it switches on wireless debugging, reads its own pairing code off the screen, and connects to the phone as a developer would.

Once it has done that, removing the app does not remove the attacker.

What the AI is actually for

RatHat, documented by Zimperium researchers Gianluca Braga, Vishnu Pratapagiri and Fernando Ortega, abuses Android's Accessibility service. It then faces the same problem as every screen-scraping trojan: banking apps do not look the same on every handset, in every language, at every version.

Its answer is to serialise the live Accessibility tree, the structure describing every visible element and its position, into XML and send it to a generative AI assistant. Zimperium's analysis records three requests: the centre coordinates of a named target, returned as JSON so the malware can synthesise a tap; the on-screen text of an element, untranslated; and navigation instructions such as scrolling down.

The model is never asked to do anything malicious, only to read a layout. The request is unremarkable to the service answering it.

Tapping Build Number seven times

The escape from the application sandbox is mechanical, and it matters more than the AI part.

With Accessibility access, the malware synthesises gestures. It opens settings and taps Build Number seven times, the standard gesture that unlocks Developer Options. Through the same automated tapping, it switches on Wireless Debugging. Android then shows a dialog containing a six-digit pairing code and a port, and the malware reads both off the screen it is already scraping.

With the code, an embedded copy of the libadb-android library authenticates against the device's own debug daemon. The result is shell-level access to a directory on the phone, with no cable, no computer, and no prompt the user would recognise as consent.

7 tapsOn Build Number, to open Developer Options
6 digitsThe pairing code it reads off screen
4 and 6Anti-analysis layers and anti-debug checks
geteventThe debugging tool it uses to log touches

Reading the PIN off raw input

Screen-lock recovery does not rely on the AI at all. A Go agent runs getevent, a standard Android debugging utility that reports raw input events, and logs the coordinates of every touch.

To turn coordinates into digits, the malware ships a file of keypad layouts for major handset brands and maps each touch to the key that sits there. For pattern locks the sequence of points is matched against the three-by-three grid.

The shell access matters more than the model because reading raw input devices is not something an ordinary application can do.

Why uninstalling does not work

RatHat first tries to stop the uninstall happening. It detects the confirmation dialog and covers it with a counterfeit failure message styled to look like Google Play, cancelling the removal.

Advertisement

If the user succeeds in removing the app, the daemon installed through the debug bridge remains. It sits outside the application lifecycle, checks whether the package is still present, and when it is not, reinstalls the APK and grants its own permissions again.

The user performed a successful uninstall. The phone is still compromised, and nothing on it says so.

How it reaches a phone

Distribution is unglamorous: text-message phishing, malicious advertising, and posts on third-party forums pushing victims to pages that offer an APK for manual download. Nothing here defeats Google Play. It defeats the decision to install from somewhere else.

The targets are banking applications, WeChat, Alipay and cryptocurrency platforms. Zimperium attributes the operation to actors who appear to be based in China, on the basis of the prompts the malware sends. Four layers of anti-analysis and six separate anti-debugging checks sit around all of it.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement