RatHat Go service staged to /data/local/tmp binds port 7912
Detects the staging of a potential RatHat malware component by observing a native Go binary being moved into /data/local/tmp via ADB shell (uid 2000), followed by an associated service binding to local port 7912 within a 5-minute window. This sequence is characteristic of the deployment process for this specific Android threat.
Microsoft Sentinel (KQL)

