The Maivia Gazette

Verified AI news, every morning

Security

RatHat Android malware uses Chinese-language LLM prompts to steer infected phones and survives its own removal

Zimperium says the trojan enables Wireless Debugging to get a shell without a PC, then installs a Go agent that restores the malware if it is uninstalled.

Editorial illustration about RatHat Android malware uses Chinese-language LLM prompts to steer infected phones and survives its own removal.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Zimperium zLabs researchers have analyzed a new Android malware family called RatHat that includes an AI-powered subsystem to help operators navigate compromised devices remotely. The researchers link it to China-based threat actors after finding large language model prompts written in Chinese inside the malware. RatHat spreads through malvertising, SMS messages and phishing sites that push APK downloads from outside Google Play. Like most Android malware, it abuses Accessibility permissions to perform privileged actions. Its notable trick is enabling Developer Options and Wireless Debugging so it gains a local shell-level execution context without an external computer, a mechanism previously seen in the ToxicPanda and RedHook families. That ADB access lets RatHat install a Go-based agent that runs commands with shell privileges, bypasses battery restrictions and manages persistence. The agent restores the malware if it is removed or stopped, and the malware restores the agent in turn, so removing either component alone does not clean the device. The Go agent also performs keylogging. A second agent acts as an FRP reverse-proxy client to give operators a channel into the phone. The Hacker News reports that the ADB abuse lets the operators retain shell access even after the app is uninstalled. Android users who sideload apps from links in ads or messages are the intended victims.

Sources

  1. BleepingComputerNew RatHat Android malware uses AI to automate device controlPublished · fetched
  2. The Hacker NewsRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallPublished · fetched

Also in this edition