RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat Android malware uses Gemini AI to identify high-value victims.
Summary
The RatHat Android banking trojan, offered as a malware-as-a-service, has been updated to use Google's Gemini AI to analyze victim data and identify those with higher bank balances. Security firm Cleafy has observed nearly 100 deployments of its web-based control console since April 2026, with the latest version leveraging AI to prioritize targets for operators. The malware gains deep access to infected phones, including screen streaming and ADB shell control, and can even reinstall itself after deletion.
Full text
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Swati KhandelwalSep 28, 2026Mobile Security / Artificial Intelligence RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups. Nothing in the samples Cleafy analyzed uses the model to move money. Its role is "deciding which victims are worth an operator's time," the company said. One Console, Three Versions The malware on victims' phones has changed little since late 2025, Cleafy said. The console behind it has been replaced. Samples from late 2025 and February 2026 connected to an earlier console named Fisher. Three new versions were in use between April and September 2026, all built from the same code. The first calls itself BlackCat Remote Control Management. The next two are named Panda Workshop V5 and V6. Every version is also a build tool. From the console, an operator can build the malware, hide it inside a harmless-looking app, and sign it. The console then publishes the finished app to Amazon S3 or to a web server, without the operator having to touch the hosting setup. The console can also rebuild the app on a schedule, such as every hour. Each rebuild creates a new file from the same malware, which Cleafy said is aimed at security tools that spot known files by their hash. The latest version also adds templates for fake download pages, including one called Google Store. Shell Access in One Click RatHat reaches phones through text messages and online ads that lead to third-party download sites, Zimperium found earlier this month. Once installed, the app asks for Accessibility access, which lets an app read the screen and tap for the user. With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android. That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app. From the console, the operator can use that shell with one click, Cleafy found. A deploy button starts a separate program written in Go that stays reachable through a reverse tunnel, a connection the phone opens to the operator's server. Pairing with ADB happens automatically, but the Go program runs only after the operator clicks deploy. That program changes how the operator can watch the screen. Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs. The Go program instead uses tools called minicap and minitouch to stream the screen and send taps, with no permission prompt and no recording icon. Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt. Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers. The Go program keeps running after the victim removes the app, until the phone restarts. Zimperium found that the program can also reinstall the app after it is deleted and turn its Accessibility access back on. Neither report provides steps to remove the malware completely. How Widely the Console Is Used Cleafy found the deployments by searching for the console's page titles and web code. The figure counts console deployments, not infected phones. Cleafy did not say what counts as one deployment, and neither its report nor Zimperium's gives several victims. The console limits the number of operator accounts and hides some sections from non-admins. Cleafy said those limits only make sense if the users are customers the developers do not fully trust. Nearly half of the IP addresses Cleafy observed are on one Singapore-registered network, AS4907. Gemini on Both Ends The first console version let operators pick from several AI providers, Cleafy found. It could also send a Telegram alert when a phone's AI score passed a set level. The latest version works only with Gemini and directs operators to Google AI Studio to get a key. RatHat also uses Gemini on the phone itself. Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate. When that happens, the malware sends the screen's layout to Gemini and asks where to tap. It calls Gemini straight from the phone, using an API key stored in its own settings. Cleafy said the feature is used only to keep the wireless debugging setup working. Android malware has done this before. PromptSpy, which ESET described in February, also sent Gemini the screen layout and followed its tap instructions. Indicators and Detection Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples: Domain: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026) Domain: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026) IP: 8.231.120[.]246 (C2 for BlackCat, April 2026) Domain: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026) URL: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026) URL: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026) MD5: 116346cace7f00ba557034b534d40791 (sample, September 2026) MD5: 8fdc21e25097a46528211274e54330e1 (sample, February 2026) MD5: f83357b2d47c7d38ee53943373961211 (sample, December 2025) The consoles tend to use web addresses that start with admin., plus adminapi. for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top. Once the Go program is deployed, the minicap and minitouch files sit in /data/local/tmp under their real names, where a scan can find them. Cleafy said security tools should watch what runs on phones as the shell user, UID 2000. One of the listed addresses, admin.xiongmaocs[.]pics, also appears in the indicator list Zimperium released with its earlier analysis. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Android, artificial intelligence, Malware, mobile security ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Z
Indicators of Compromise
- mitre_attack — T1059.004
- mitre_attack — T1115
- mitre_attack — T1071.001
- mitre_attack — T1027
- mitre_attack — T1566.001
- mitre_attack — T1566.002