Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
Cleafy's RATHat Android trojan uses Gemini Flash to navigate UIs and keeps shell persistence after app removal.
Cleafy documented RATHat, an Android banking trojan that sends the live Accessibility UI tree to Google Gemini Flash and uses the model's JSON coordinates to tap controls across device variants. After social engineering grants Accessibility, it enables Wireless Debugging, reads the on-screen ADB pairing code, and obtains shell access as UID 2000. A Go service in /data/local/tmp opens an FRP reverse tunnel and can reinstall the app with permissions if the APK is removed, lasting until reboot. Its Panda Workshop panel, evolved from an earlier BlackCat console between April and September 2026, rates stolen SMS for financial value, rebuilds signed APKs on a schedule, and is linked to nearly 100 deployments across Europe, Latin America, and Southeast Asia.
- RATHat tricks users into enabling Accessibility, then pairs over local ADB.
- Gemini Flash reads the live UI tree and returns control coordinates as JSON.
- A Go agent in /data/local/tmp survives APK removal until reboot.
- Panda Workshop scores SMS for victim value and rebuilds APKs to evade hashes.
- Nearly 100 deployments since April 2026 span Europe, Latin America, and Southeast Asia.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | chunhuating.best | ndicators of Compromise Type Value Description Domain admin.chunhuating[.]best Sep 2026 C2 (Panda V6) Domain admin.xiongmaocs[.]pics Aug |
| domain | dramaspoolcoa.com | n.rathat[.]live Dec 2025 / Feb 2026 C2 (Fisher) URL https://dramaspoolcoa[.]com/en.html Sep 2026 Delivery Note: IP addresses and domains |
| domain | rathat.live | 5) IPV4 8.231.120[.]246 Apr 2026 C2 (BlackCat) Domain admin.rathat[.]live Dec 2025 / Feb 2026 C2 (Fisher) URL https://dramaspoolcoa |
| domain | xiongmaocs.pics | dmin.chunhuating[.]best Sep 2026 C2 (Panda V6) Domain admin.xiongmaocs[.]pics Aug 2026 C2 (Panda V5) IPV4 8.231.120[.]246 Apr 2026 C2 ( |
Full article922 words · extracted from gbhackers.com · click to collapse
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware.
The threat uses Google Gemini models to navigate unfamiliar Android interfaces, while its operator panel applies AI to identify higher-value victims from stolen SMS data.
The malware disguises itself as legitimate applications, then relies on social engineering to persuade victims to enable Android Accessibility Services. That initial permission becomes the gateway to a far more invasive attack chain.
Once Accessibility access is granted, RATHat automatically enables Developer Options and Wireless Debugging, collects the local Android Debug Bridge pairing code from the screen, and pairs with the device’s own ADB daemon.
This gives the malware shell-level access as Android’s shell user, UID 2000, rather than merely the permissions assigned to the malicious APK.
It can then stage a native Go-based service in /data/local/tmp and deploy an FRP client to create a reverse tunnel to attacker-controlled infrastructure.
This architecture fundamentally changes the defender’s problem. The malicious application is no longer the only component that matters.
The Go agent runs outside the app’s normal process lifecycle and can continue operating even if the victim removes the visible APK.
According to the research, the service can check whether the app remains installed and reinstall it with runtime permissions, while restoring Accessibility settings through shell commands.
The result is persistence that survives app removal until the device is rebooted or the malicious shell-level components are removed.

The most notable feature is RATHat’s use of Gemini to overcome a long-standing limitation in Android fraud automation: device fragmentation.
Conventional banking trojans depend on static UI locators and scripted taps, which can fail when a victim uses a different Android version, language, OEM skin, or display layout.
RATHat serializes the live Accessibility UI tree into XML and submits it to Gemini Flash models, asking the model to identify a specific control, return its screen coordinates as JSON, resolve visible text, or advise navigation actions.
The malware stores an API key in its configuration and uses low-temperature, short-output prompts suited to machine-driven decisions rather than chat.
Cleafy said in a report shared with GBhackers, RATHat is distributed through smishing, malvertising, deceptive download portals and third-party forums.
Gemini-Powered Malware
In practical terms, Gemini is being used as an adaptive UI-navigation component. If RATHat cannot find “Wireless debugging,” a pairing option, or another required settings control through predefined logic, the model can help it locate the element and continue the infection sequence.
This reduces the need for developers to manually engineer reliable automation for every Android variant and localization.
RATHat’s AI integration also extends to the operator side. The malware’s evolving command-and-control ecosystem, reportedly rebranded from BlackCat to Panda Workshop, includes functions for analysing intercepted SMS messages and estimating victims’ financial value.

The panel can extract apparent account balances, assign AI-driven device ratings and organize compromised devices into categories such as analysed, high-value and mid-value targets.
This allows operators to prioritize victims without manually reviewing every message collected from infected phones.
The C2 panel reportedly evolved through three versions between April and September 2026, despite limited changes to the implant itself.
It acts as a malware-production platform capable of building, packing, signing and publishing APKs from a web interface.
Scheduled rebuilds can regenerate samples at fixed intervals, undermining hash-based detections by continuously producing new file artifacts.
When the malware boots up, it retrieves the list of global templates through /api/injection/global-configs that are preloaded in the panel.
The latest Panda Workshop version also adds phishing download-page templates, including layouts designed to resemble a “Google Store” page.

Researchers identified nearly 100 distinct deployments associated with the panel infrastructure since April, with campaigns observed across Europe, Latin America and South-Eastern Asia.
Licensing controls, account caps and role-based operator features suggest the infrastructure may support a Malware-as-a-Service model in which multiple affiliates operate dedicated instances.
For defenders, RATHat reinforces that monitoring must extend beyond malicious APK signatures.
High-priority indicators include unexplained Accessibility activation, Wireless Debugging enablement, local ADB pairing activity, shell processes running under UID 2000, suspicious binaries in /data/local/tmp, and outbound reverse-proxy connections.
Financial organizations should also treat unexpected overlay activity, screen-capture behavior and raw-input access as high-risk signals, particularly on devices that have enabled developer-facing debugging functions.
The broader concern is not only that RATHat steals credentials and OTPs, but that it turns AI into a resilient on-device decision engine.
Gemini is not conducting the fraud itself; it is helping malware adapt when scripted automation encounters the real-world complexity of Android devices.
That capability makes automated fraud campaigns more scalable, less dependent on per-target customization and potentially more difficult to disrupt.
Indicators of Compromise
| Type | Value | Description |
|---|---|---|
| Domain | admin.chunhuating[.]best | Sep 2026 C2 (Panda V6) |
| Domain | admin.xiongmaocs[.]pics | Aug 2026 C2 (Panda V5) |
| IPV4 | 8.231.120[.]246 | Apr 2026 C2 (BlackCat) |
| Domain | admin.rathat[.]live | Dec 2025 / Feb 2026 C2 (Fisher) |
| URL | https://dramaspoolcoa[.]com/en.html | Sep 2026 Delivery |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.