Google has activated its developer verification system on certified Android devices in Brazil, Indonesia, Singapore, and Thailand, blocking installation of apps from unverified developers by default. A global rollout is planned for 2027. Users can still sideload apps via methods including Google's multi-step Advanced Flow, ADB, Shizuku, rooting, or custom ROMs such as LineageOS and GrapheneOS.
androidauthority.com
· 2026-10-01
Security firm Zimperium has identified RatHat, a new Android malware strain that tricks users into installing a fake app resembling Google Chrome through a spoofed Play Store page. Once granted accessibility permissions, it silently enables developer-level ADB Shell access, deploys an AI-driven agent to run system commands, and funnels stolen data to remote servers. Researchers have already found 162 infected apps tied to roughly a dozen attacker-controlled servers, with China-linked actors primarily targeting payment apps like WeChat Pay and Alipay.
cnet.com
· 2026-09-20
Zimperium zLabs identified a new Android malware family, RatHat, spread via malvertising, SMS and phishing sites offering APK downloads outside Google Play. It abuses Accessibility permissions and enables Developer Options and Wireless Debugging to gain shell-level control, installing companion agents that maintain persistence, log keystrokes, and steal banking or crypto credentials through fake overlays. Researchers link the operation to Chinese-speaking actors based on Chinese-language prompts found in its AI automation engine.
bleepingcomputer.com
· 2026-09-17