RatHat: shell-UID minicap/minitouch/Go daemon staged in /data/local/tmp

Detects malicious staging and C2 activity characteristic of RatHat Android malware. The rule identifies processes running under the Android shell user (UID 2000) that execute specific tools (minicap, minitouch, or disguised libraries) from the /data/local/tmp directory, followed by an outbound network connection, which is indicative of a persistence mechanism and reverse-tunneling command-and-control communication.