RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android banking trojan uses Gemini to pair wireless debugging and control phones beyond normal app permissions.
Cleafy reports RATHat, an Android banking trojan distributed through malicious ads and phishing texts in Europe, Latin America, and Southeast Asia. After Accessibility access, it enables wireless debugging, pairs with local ADB as UID 2000, and queries Gemini Flash from the device when interface matching fails. Operators can then deploy an independent Go service on port 7912 that captures the screen and injects touches through a reverse tunnel and survives app removal until reboot. Cleafy identified nearly 100 deployments since April 2026 and panel generations from BlackCat to Panda Workshop V6, consistent with malware-as-a-service.