RatHat: Accessibility abuse chained to ADB self-pairing (shell UID 2000)

Detects a specific Android sandbox escape technique where a malicious app enables Accessibility Services and Developer Options/Wireless Debugging to initiate a self-pairing ADB connection over localhost. This bypasses typical app sandbox restrictions, allowing the execution of processes with the UID 2000 (shell) context.