bypassing protections

AppWizard
September 19, 2026
Security researchers have identified an Android banking Trojan named RatHat, which utilizes artificial intelligence, accessibility features, and Android Debug Bridge (ADB) to steal financial credentials, PINs, and one-time passcodes. Unlike traditional malware, RatHat employs a live AI assistant that interacts with the Android accessibility tree, allowing it to make real-time decisions based on the victim's screen content. The infection typically starts with social-engineering tactics, leading victims to counterfeit download pages where they are tricked into sideloading a malicious APK. Once installed, RatHat prompts users to enable Android Accessibility Service permissions, which it exploits to navigate Developer Options and enable Wireless Debugging. This grants it shell-level ADB access, allowing it to bypass application sandbox restrictions. RatHat deploys two native binaries for executing commands and maintaining a connection to the attacker's infrastructure. It targets banking applications through credential-stealing overlays and can intercept SMS messages for transaction verification codes. Additionally, it can record touch coordinates to reconstruct PINs and unlock patterns. RatHat includes persistence mechanisms to restore itself after removal, and users are advised to perform a factory reset if they suspect compromise. To reduce infection risk, users should avoid sideloading apps from unknown links, deny unnecessary Accessibility Service requests, and refrain from enabling Developer Options or Wireless Debugging for unfamiliar applications.
Winsage
August 6, 2024
Elastic Security Labs has identified techniques that malicious actors may use to bypass Windows security alerts, particularly targeting Windows SmartScreen and Smart App Control (SAC). One method, known as "LNK Stomping," exploits a flaw in how Windows handles shortcut files (.LNK) to nullify the Mark of the Web (MotW) tag, which indicates potentially dangerous files. This technique allows malware to evade detection since SmartScreen only scans files with the MotW tag. The technique involves creating LNK files with unconventional target paths, prompting Windows Explorer to correct these discrepancies and remove the MotW tag. Desimone noted that this vulnerability has been present for over six years, with samples found in VirusTotal. Other methods to bypass reputation-based protections include signing malicious applications with code-signing certificates, Reputation Hijacking, Reputation Seeding, and Reputation Tampering. These methods manipulate legitimate programs or create seemingly trustworthy binaries to exploit vulnerabilities in the system.
Search