Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

RatHat Android Trojan Leverages Accessibility Service to Hijack Devices and Steal Credentials

A new Android trojan, RatHat, abuses Accessibility Service to silently enable debugging and exfiltrate credentials, illustrating gaps in mobile device controls and user awareness. Organizations must tighten MDM policies and train users to mitigate this threat.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

RatHat Android Trojan Leverages Accessibility Service to Hijack Devices and Steal Credentials

What Happened — RatHat, a new Android trojan identified by Zimperium, abuses the Accessibility Service to silently enable Developer Options, activate Wireless Debugging, and pair with the device’s ADB interface without user interaction. The malware is delivered via smishing, malvertising, and deceptive APKs, then uses encrypted payloads and anti‑analysis tricks to maintain persistence and exfiltrate credentials.

Why It Matters for Trust & Control Assurance —

  • Demonstrates the risk of unchecked privileged Android APIs; continuous monitoring of Accessibility and debugging settings is a core control‑assurance requirement.
  • Highlights the need for robust mobile‑device‑management (MDM) policies that enforce app vetting and restrict developer‑mode activation.
  • Shows how social‑engineering delivery vectors bypass traditional perimeter defenses, underscoring the importance of security awareness training and evidence of user‑behavior controls.

Who Is Affected — Enterprises with BYOD programs, mobile‑app developers, telecom carriers, and any organization whose workforce relies on Android devices.

Recommended Actions —

  • Enforce MDM policies that block third‑party apps from requesting Accessibility Service and automatically disable Developer Options on unmanaged devices.
  • Deploy security awareness campaigns focused on smishing and malicious app downloads.
  • Implement continuous monitoring for anomalous ADB connections and log all Accessibility Service usage for auditability. Source: https://securityaffairs.com/199317/malware/rathat-turns-android-accessibility-into-an-attack-weapon.html

Technical Notes — RatHat uses encrypted dropper files, reflection‑based DEX loading, and native SessionInstaller APIs to bypass installation restrictions. It also employs anti‑analysis techniques such as malformed ZIP containers and encrypted strings. Source: https://securityaffairs.com/199317/malware/rathat-turns-android-accessibility-into-an-attack-weapon.html

📰 Original Source
https://securityaffairs.com/199317/malware/rathat-turns-android-accessibility-into-an-attack-weapon.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →