RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Cleafy details RatHat Android banking trojan's malware-as-a-service console, which uses Google Gemini to rank victims by bank balance and guide on-device taps.
Cleafy traced nearly 100 deployments of the RatHat Android banking trojan's web console since April 2026, consistent with a malware-as-a-service model spanning Fisher, BlackCat Remote Control Management, and Panda Workshop V5/V6 versions. The console stores stolen SMS and passwords harvested via fake login overlays on banking apps, and its latest version uses Google's Gemini to estimate each victim's bank balance and sort devices into high- and mid-value groups. On-device, the trojan abuses Accessibility access to enable wireless debugging and pair with ADB, yielding a shell running as UID 2000, while a Go program maintains a reverse tunnel and streams the screen via minicap/minitouch without permission prompts. The malware also sends screen layouts to Gemini for tap guidance when built-in instructions fail, mirroring ESET's PromptSpy findings from February.