Chinese-linked RatHat Android Malware Exploits ADB Pairing to Hijack Banking Apps
Security researchers have uncovered a sophisticated Android banking trojan, dubbed RatHat, that leverages the Android Debug Bridge (ADB) pairing feature to obtain shell-level control on compromised devices and harvest users’ banking PINs.
The malware combines several techniques, including abuse of the Accessibility service to automate user interface interactions, local ADB pairing to establish a privileged connection, and native code that runs with root‑like permissions. By automating the entry of credentials, the threat can silently siphon PIN numbers from a wide range of banking applications without alerting the victim.
Analysis of the code suggests that the developers employed generative‑AI tools to streamline the creation of the UI‑automation scripts, a practice that has become more common among financially motivated threat actors. The ADB abuse is particularly notable because it bypasses the usual sandbox that separates apps from the operating system, allowing the malicious payload to execute commands directly in the device’s shell.
Investigators trace the infrastructure behind RatHat to servers hosted in China, and the operational patterns align with previously documented campaigns attributed to Chinese‑based cybercrime groups. The malware’s distribution appears to rely on repackaged legitimate apps and malicious advertising networks, making it difficult for average users to spot the infection before the banking modules activate.
Experts warn that the emergence of RatHat highlights the growing risk of Android devices being turned into covert banking fraud tools. Users are urged to disable ADB debugging when not actively using development features, avoid installing apps from untrusted sources, and monitor banking activity closely. Mobile security firms say they are updating detection signatures and encouraging carriers to block suspicious ADB pairing requests. The discovery also underscores the need for tighter vetting of app permissions and for Google to reinforce safeguards around the Accessibility and ADB APIs.
Comments (0)
Be the first to comment.
Join the discussion