← Back to Feed
New RatHat Android malware uses AI to automate device control
September 17, 2026 · BleepingComputer · Severity: HIGH
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.
Key Takeaways
- RatHat Android malware abuses Android Debug Bridge (ADB) to retain shell access after initial compromise, enabling persistent remote control of infected devices.
- The malware leverages ADB debugging features that are typically enabled during development, underscoring the importance of disabling USB debugging on production devices.
- Organizations should enforce policies that disable ADB on enterprise-managed Android devices and monitor for unauthorized ADB connections as a detection indicator.