← Back to Feed

New RatHat Android malware uses AI to automate device control

September 17, 2026 · BleepingComputer · Severity: HIGH

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.

Key Takeaways

  • RatHat Android malware abuses Android Debug Bridge (ADB) to retain shell access after initial compromise, enabling persistent remote control of infected devices.
  • The malware leverages ADB debugging features that are typically enabled during development, underscoring the importance of disabling USB debugging on production devices.
  • Organizations should enforce policies that disable ADB on enterprise-managed Android devices and monitor for unauthorized ADB connections as a detection indicator.
☕ Buy a Coffee