Drama RAT Android: Remove a Hidden App After a Fake VPN Update

Brendan Smith
Brendan Smith - Cybersecurity Analyst
8 Min Read
Drama RAT hidden inside an Android phone after a fake uninstall
An app that appears to disappear can remain active on an Android phone.

Drama RAT is Android banking malware that can make an app appear to uninstall while it keeps running. If a sideloaded VPN demanded another installation, then disappeared or started bouncing you out of Settings, stop using that phone for banking. Check the installed-app list and use your phone manufacturer’s Safe mode instructions if normal removal is blocked. Removing an icon is not the same as removing an app.

The useful question is how far the installation went. A downloaded APK, an installed launcher, a second app and an enabled Accessibility service call for different responses. This guide separates those stages so you can identify what needs attention without deleting legitimate phone features.

Recognize the fake update and fake deletion

Positive Technologies’ September 2026 research describes Drama RAT arriving through messaging lures disguised as VPNs and other apps. The first app asks for an update that installs a separate malicious component. Accessibility access lets the trojan interact with the screen and interfere with attempts to revoke permissions. [1]

Fake Update Required screen in a Drama RAT dropper
The installer asks for another update. Its Google Play protection label is part of the lure, not proof of verification. Source: Positive Technologies.

The researchers also documented an incompatibility message pretending to remove the app. Instead, its icon disappears. Attempts to open app settings can return the user to the Home screen. These are stronger reasons to investigate than battery drain alone, but they do not identify a malware family by themselves.

Match the response to what you allowed

  • You only saw the link or downloaded an APK. Do not open or install it. Delete the download. A web page claiming your phone is infected does not establish an installation; use the Android malware and fake-alert guide if the warning stays inside your browser.
  • You installed the first app but declined its update. Remove that app and its downloaded installer. Do not reopen it to check whether the offer was genuine. Declining the second installation is useful context, not a reason to trust the first app.
  • You accepted the update or enabled Accessibility. Look for both the original app and the later installation. Do not limit your check to the VPN’s familiar display name or launcher icon.
  • The phone blocks Settings, enters text or opens screens unexpectedly. Stop entering credentials. If you can, disconnect Wi-Fi and mobile data while arranging recovery from another device. If control is unreliable, power the phone off and obtain the manufacturer’s recovery instructions elsewhere.

Remove the app when Settings keeps closing

Use the steps for your exact manufacturer and model. Safe mode is a diagnostic environment, not a factory reset. Samsung states that third-party apps do not run in this mode and can be removed there. [2]

  1. Enter Safe mode. On supported Galaxy devices, power off, start the phone, and hold Volume down when the Samsung logo appears. Confirm that the screen says Safe mode. Samsung also provides a Power-menu method: touch and hold Power off, then choose Safe mode. Other brands may use different steps.
  2. Inspect Settings → Apps. Identify installations associated with the incident. Record the app name and package identifier if shown. An app can be present here even when its launcher icon is gone.
  3. Review the identified app’s access. If accessible, turn off its untrusted service under Accessibility and review its special permissions. Do not disable every Accessibility service: screen readers and other assistive tools legitimately use them. On a work-managed phone, involve IT before changing management controls.
  4. Uninstall the suspect components. Remove the original installer app and the later app you identified, then delete the downloaded APKs. Removing only the download leaves an installed application in place.
  5. Restart normally and check again. Confirm that app settings stay open, the removed apps remain absent and their services do not return. A normal restart alone is not a cleanup procedure.

If you cannot identify the apps or regain control, stop guessing package names. Contact the manufacturer or your organization’s support team. These are general Android recovery steps matched to the reported behavior; they are not a laboratory-tested removal procedure for every Drama RAT variant.

Check the phone and secure accounts separately

Once you have control of the device again, enable Google Play Protect, check for Android and security updates, and review installed apps. Google recommends manufacturer help or a reset if malware signs continue. [3] Reconnect for updates only after the suspected apps have been removed or support has guided your recovery.

For an additional installed-app check, use Gridinsoft Trojan Scanner for Android after manual removal. Review its findings and recheck if an app or symptom returns. Use the Android tool for the phone; a scan result does not establish what happened to your accounts during the exposure.

If you entered banking details, approved transactions or used sensitive accounts while the phone behaved this way, contact the relevant provider from a separate trusted device. Review transactions, terminate unfamiliar sessions and change affected passwords there. Do not approve unexpected verification prompts on the suspect phone. Local cleanup does not reverse an unauthorized transfer or cancel an already stolen session.

Before a factory reset, make sure you can recover your accounts and essential data. Follow the manufacturer’s process, then reinstall needed apps from their official sources instead of restoring the suspicious APKs. If symptoms return before those apps are restored, get support rather than repeating the same reset.

FAQ

Does this mean my legitimate VPN is Drama RAT?

No. A VPN name, icon or ordinary update request cannot identify the malware. Compare where the app came from, what extra installation it requested and what happened afterward. Keep an uncertain app removed while you verify its source; do not reinstall it just because its name resembles a legitimate service.

References

  1. Positive Technologies. “Drama RAT — вредоносное приложение, после установки которого действительно становится печально.” Habr, September 4, 2026; accessed September 12, 2026. Research report and application screens.
  2. Samsung. “Power on your Galaxy phone or tablet in Safe mode.” Samsung Support, accessed September 12, 2026. Galaxy Safe mode instructions.
  3. Google. “Remove malware or unsafe software.” Google Account Help, Android instructions, accessed September 12, 2026. Android cleanup and security checks.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?