ADVERTISEMENT

This Android malware is nuts: it connects to your phone like a developer, but from the inside

The game-changing Android malware abuses the legitimate developer ADB tool to gain access it should never have.

android malware

Android malware. Image by Cybernews, Unsplash/Pham Nhat, Shutterstock/Overearth

Ernestas Naprys
Ernestas Naprys Senior Journalist
September 18, 2026 Updated: 7 minutes ago 4 min read
Key takeaways:

How do you get infected?

In some countries, it claims permission is needed "due to network restrictions" and offers financial bait,
the Zimperium researchers said.
developer options rathat
Malware itself enables ADB. Image by Zimperium.
ADVERTISEMENT

How do attackers exploit this powerful access?

  • The Go agent, which turns ADB access into persistent control. This package executes commands that bypass the user-facing application limitations, making the malware harder to stop, preventing it from sleeping, disabling other apps, or even uninstalling security-related apps.
  • Reverse-proxy client, frpc. Its only function is to maintain a secure persistence tunnel to the command-and-control server.
rathat malware
architecture and operational flow of RatHat malware. Image by Zimperium

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites

Paradigm shift

ADVERTISEMENT