RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
Cleafy details RatHat Android banking trojan's C2 panel evolving into a Gemini-powered malware-as-a-service platform that ranks victims by estimated bank balance.
Cleafy research published September 28 shows the RatHat implant changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop. Nearly 100 deployments since April 2026 support a malware-as-a-service model, with campaigns across Europe, Latin America, and Southeast Asia; almost half of observed IPs sat on one Singapore-based network. The latest panel uses Google Gemini to analyze stolen SMS messages and estimate victims' bank balances, sorting devices into high-value and mid-value groups. Operators can also deploy a native Go service via wireless debugging for shell-level control outside Android's permission model, persisting until reboot.