RatHat is an Android banking malware campaign that combines social engineering, Accessibility abuse, wireless debugging, and automated device control. Attackers distribute malicious APKs through SMS phishing, malvertising, deceptive download portals, and third-party websites. The malware uses a multi-stage architecture involving a malicious Android application, a Go-based agent, and a reverse-proxy component. Its command-and-control infrastructure supports malware generation, deployment, victim monitoring, and automated management. The infection begins when a victim is tricked into installing a malicious APK outside the official Google Play Store. The malware requests Accessibility Service privileges and abuses them to interact with the device, enable Developer Options and wireless debugging, and obtain the ADB pairing code. RatHat then pairs with the Android Debug Bridge, enabling shell-level execution and bypassing normal application restrictions. The Go-based agent establishes persistence and modifies power-management settings to maintain execution. After gaining shell access, RatHat deploys a reverse-proxy client that creates a tunnel to attacker-controlled infrastructure, providing broader remote access. The malware can steal SMS messages, credentials, files, browser information, screen content, installed applications, and lock-screen credentials. It can also display overlays that imitate legitimate banking and cryptocurrency applications. AI-assisted screen analysis helps identify interface elements and perform automated interactions, allowing attackers to adapt to changing application layouts. Organizations should strengthen controls against Android sideloading and excessive application privileges. Users should avoid APKs received through SMS, advertisements, or unofficial websites and grant Accessibility Service permissions only to trusted applications. Developer Options and wireless debugging should remain disabled unless required. Security teams should monitor for unexpected Accessibility permissions, wireless-debugging activity, ADB shell execution, suspicious reverse-proxy connections, unauthorized APK installations, and abnormal shell-level processes. Suspected devices should be isolated and investigated promptly, with credentials reset where compromise is confirmed.
A newly demonstrated security flaw in LibreOffice and Apache OpenOffice shows how seemingly legitimate spreadsheet features can be combined to execute malicious code without the us...
Four vulnerabilities disclosed in Apache Struts could expose affected applications to remote code execution, denial of service, resource exhaustion, and cross-user data disclosure....
Atlassian has disclosed a critical arbitrary file access vulnerability, CVE-2026-21589, affecting Jira Software Data Center and Confluence Data Center. Rated CVSS 9.3, the flaw all...