Skip to content

Topic

Accessibility Service Abuse

Attacker use of legitimate Android accessibility grants to bypass consent prompts, escalate privilege and persist without exploiting vulnerabilities.

Current stories

security6 publishers

ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell

Zimperium says the Android banking Trojan now abuses Accessibility to switch on wireless debugging and run commands through the ADB daemon. The target list is the smaller half of the story.

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 67%
Investor
Investor 5%

Reality

Evidence62
Adoption
Insufficient
Hype gap+12
Incentives55
Confidence64
security6 publishers

RatHat self-pairs Android's debug bridge to survive its own uninstall

Zimperium says RatHat uses an accessibility grant to switch on Wireless Debugging and read its own 6-digit pairing code, leaving native daemons at shell privilege that keep answering after the app is removed.

Perspective Coverage

6 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence62
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence66