Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
Cleafy's RATHat Android trojan uses Gemini Flash to navigate UIs and keeps shell persistence after app removal.
Cleafy documented RATHat, an Android banking trojan that sends the live Accessibility UI tree to Google Gemini Flash and uses the model's JSON coordinates to tap controls across device variants. After social engineering grants Accessibility, it enables Wireless Debugging, reads the on-screen ADB pairing code, and obtains shell access as UID 2000. A Go service in /data/local/tmp opens an FRP reverse tunnel and can reinstall the app with permissions if the APK is removed, lasting until reboot. Its Panda Workshop panel, evolved from an earlier BlackCat console between April and September 2026, rates stolen SMS for financial value, rebuilds signed APKs on a schedule, and is linked to nearly 100 deployments across Europe, Latin America, and Southeast Asia.