@kazani
RatHat can keep shell access to an Android device even after the malicious app is uninstalled.
It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.
How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html