
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have identified a new Android malware called RatHat, assessed to be operated by China-based threat actors. RatHat is distributed via targeted smishing and malvertising campaigns that lead to deceptive third-party download portals. The malware abuses Android Debug Bridge (ADB) to retain shell access on compromised devices even after the malicious app is uninstalled, and features an AI-powered system to navigate and control devices.
