RatHat Android Malware: Fake Chrome App Can Take Over Your Phone

An Android user opens Google Chrome on a smartphone as researchers warn that RatHat malware can disguise itself as legitimate apps to gain deeper access to infected devices.

An Android user opens Google Chrome on a smartphone as researchers warn that RatHat malware can disguise itself as legitimate apps to gain deeper access to infected devices. Image: Generated via Google’s Nano Banana

RatHat Android malware can pose as Google Chrome, abuse Accessibility and ADB, steal credentials, and reinstall itself after removal.

Written By
Matt Gonzales
Matt Gonzales
Sep 21, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

That Google Chrome download may be hiding something much nastier.

Security researchers have uncovered RatHat, a new Android malware strain that can disguise itself as legitimate apps, including by using a "Chrome" label, before abusing Android permissions to gain deep control over a victim's phone. The malware can capture passwords, PINs, and authentication codes, and can even reinstall itself after a user tries to remove it.

RatHat is not exploiting a vulnerability in Chrome. Instead, attackers use deceptive download sites and other social-engineering tactics to convince Android users to sideload malicious APK files.

RatHat can disguise itself as Chrome

Mobile security researchers at Zimperium discovered that RatHat was being distributed primarily through smishing and malicious advertisements that led victims to deceptive third-party download portals.

The malicious Android application can masquerade as legitimate software. Zimperium found one build configured to impersonate a well-known streaming app, while RatHat's dynamic configuration allows operators to change its launcher icon and label, including enabling an activity alias labeled "Chrome."

CNET reported that victims can encounter fake download pages that resemble the Google Play Store and are tricked into installing what appears to be Chrome. That distinction matters: RatHat does not exploit Chrome itself. Instead, familiar apps and branding can lure victims into installing malware outside Google's official app store.

Once installed, RatHat uses social engineering to obtain Android Accessibility permissions, but its infection chain goes further. Zimperium found that its dropper uses Android's native SessionInstaller APIs to bypass restricted settings and Accessibility Service protections during installation.

After Accessibility access is granted, RatHat can automatically navigate Android settings, unlock Developer Options, enable Wireless Debugging, and obtain the six-digit pairing code used by Android Debug Bridge, or ADB.

The malware then uses embedded ADB components to pair with the device's local ADB daemon, establishing shell-level access autonomously without requiring an external computer to complete the process.

Android malware has increasingly targeted legitimate system capabilities to gain greater control. ToxicPanda 2.0 similarly abuses Android features to attack financial apps.

Advertisement

AI helps RatHat navigate the phone

RatHat also incorporates generative AI into its device-control system.

According to Zimperium, the malware can serialize information from Android's live Accessibility tree into XML and communicate with a popular generative AI assistant that the researchers did not identify. The AI can help locate interface elements, interpret text displayed on the screen, and provide navigation instructions such as scrolling.

Zimperium says this approach makes RatHat's automation more adaptable than traditional scripted techniques that depend on predefined interface elements and actions.

Once RatHat establishes deeper access, it can deploy a Go-based agent with ADB shell privileges. A separate reverse-proxy client establishes a persistent tunnel to attacker-controlled infrastructure, giving operators continued access to the device.

RatHat can also display fake interfaces over banking and payment apps, intercept SMS messages and notifications, capture credentials and authentication codes, and monitor touch input to reconstruct PINs, passwords, and unlock patterns.

Those capabilities put RatHat in an increasingly crowded field of sophisticated Android threats. The recently discovered Manic malware can also steal credentials and PINs and relay them through other infected phones.

RatHat's persistence mechanism makes it particularly difficult to remove.

Zimperium found that the malware can intercept an uninstall attempt and display a fake failure message styled to look like Google Play. Even if a user successfully removes the malicious Android app, RatHat's local service operates outside the app's package lifecycle and can remain on the device.

That service can check whether the malicious app is still installed. If it is missing, RatHat can reinstall the APK and automatically restore runtime permissions and Accessibility access.

What Android users should do about RatHat

RatHat still needs users to open the door. The malware is distributed through tactics including malicious ads, text messages and deceptive download pages, giving users several opportunities to stop an infection before attackers gain deeper control.

Android users can reduce their risk by taking a few precautions:

  • Stick to trusted app stores. Avoid installing APK files delivered through text messages, online ads, or unfamiliar websites. A page that looks like Google Play may not actually be Google's official store.
  • Be suspicious of unexpected Chrome downloads. If Chrome is already installed, don't trust any website or message that claims you need to download or reinstall it from another source.
  • Check Accessibility permissions. RatHat relies on Accessibility access as part of its path toward deeper device control. Apps without a legitimate reason to control the screen should not have this permission.
  • Watch Developer Options and Wireless Debugging. Unexpected changes to these settings could be a warning sign, particularly on devices where they are normally disabled.
  • Keep Android updated and Play Protect enabled. Google recommends keeping Android and Google Play system updates current, enabling Play Protect, and removing apps that users don't recognize, trust, or remember installing.
Advertisement

Users who think RatHat has already compromised their phone should treat the situation more seriously than a normal unwanted app. Simply deleting the suspicious application may not be enough because RatHat's separate local service can survive removal of the primary app and reinstall it.

If signs of malware continue, Google says users may need to reset their Android device or contact their device manufacturer for help. A factory reset erases the device's data, so users should review Google's reset and backup instructions before taking that step.

Users should also change passwords for banking, email, and other sensitive accounts from a separate trusted device and review those accounts for unauthorized activity.

The simplest defense comes much earlier in the attack: don't trust an unexpected Chrome download simply because the page offering it looks like Google Play.

Related reading: For another Android threat, read how Mantax Otax combines spyware and ransomware to steal data and take control of infected phones.


Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.