RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android banking trojan uses Gemini to pair wireless debugging and control phones beyond normal app permissions.
Cleafy reports RATHat, an Android banking trojan distributed through malicious ads and phishing texts in Europe, Latin America, and Southeast Asia. After Accessibility access, it enables wireless debugging, pairs with local ADB as UID 2000, and queries Gemini Flash from the device when interface matching fails. Operators can then deploy an independent Go service on port 7912 that captures the screen and injects touches through a reverse tunnel and survives app removal until reboot. Cleafy identified nearly 100 deployments since April 2026 and panel generations from BlackCat to Panda Workshop V6, consistent with malware-as-a-service.
- RATHat uses Accessibility to enable wireless debugging and pair with ADB.
- Gemini Flash suggests taps when on-screen labels do not match.
- A separate Go service on port 7912 survives app removal until reboot.
- Cleafy tracked nearly 100 deployments and three operator-panel generations.
- Distribution uses malicious ads and phishing texts across three regions.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | chunhuating.best | compromise (IoCs):- Type Indicator Description Domain admin.chunhuating[.]best September 2026 command-and-control infrastructure, Panda |
| domain | dramaspoolcoa.com | 026 command-and-control infrastructure, Fisher. URL https://dramaspoolcoa[.]com/en.html September 2026 delivery page. MD5 116346cace7f00b |
| domain | rathat.live | command-and-control infrastructure, BlackCat. Domain admin.rathat[.]live December 2025 and February 2026 command-and-control infra |
| domain | rathat.me | 557034b534d40791 September 2026 malware sample. URL https://rathat[.]me/app-release-rat-hat-live.apk December 2025 and February 2 |
| domain | xiongmaocs.pics | and-control infrastructure, Panda Workshop V6. Domain admin.xiongmaocs[.]pics August 2026 command-and-control infrastructure, Panda Wor |
| md5 | 116346cace7f00ba557034b534d40791 | amaspoolcoa[.]com/en.html September 2026 delivery page. MD5 116346cace7f00ba557034b534d40791 September 2026 malware sample. URL https://rathat[.]me/app- |
Full article925 words · extracted from cybersecuritynews.com · click to collapse
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots.
Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia.
Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three generations of the malware’s operator panel between April and September 2026.
Samples from late 2025, February 2026 and current campaigns retained a similar design, while the infrastructure behind them changed substantially. Earlier campaigns used cryptocurrency trading and adult entertainment decoys.
Cleafy said in a report shared with Cyber Security News (CSN) that nearly 100 separate deployments had appeared since April 2026.
.webp)
Licensing restrictions and parallel campaigns support a malware-as-a-service model, rather than proving one central group controls every deployment.
RATHat Android Malware
After receiving Accessibility access, RATHat navigates the phone’s settings, enables wireless debugging and reads the pairing code displayed on screen. It pairs with the local Android Debug Bridge service, gaining access as the shell user, identified by Android as UID 2000.
The pairing process relies on finding specific controls, but fixed instructions can fail on unfamiliar manufacturer interfaces, Android versions or languages. When that happens, the malware sends Gemini a structured description of the live interface and asks where to tap.
Gemini returns coordinates or short text that helps resolve an unfamiliar label. Requests go directly from the phone to Gemini Flash models using a key stored in the malware configuration, rather than passing through the attackers’ command server.
This resembles the adaptive navigation seen in Gemini assisted Android spyware that replaces rigid screen instructions with model responses.
.webp)
In RATHat, however, the observed device-side AI function specifically keeps the wireless-debugging pairing sequence working when ordinary text matching fails.
Once pairing succeeds, an operator can deploy a separate service written in Go with one click. It runs independently of the app, opens a local HTTP server on port 7912 and remains reachable through a reverse tunnel to the attacker’s infrastructure.
The service can capture screen content and inject touches using Android testing tools without the usual screen-recording prompt or indicator.
Cleafy noted that those tools do not work on Android 14 and later, leaving newer devices dependent on app-based capture with user consent.
Fraud Infrastructure
The command panel evolved from BlackCat into Panda Workshop V5 and V6. V5 introduced operator two-factor authentication and an AI balance-scoring widget, while V6 obscured its frontend code, added phishing download-page templates and consolidated AI settings around Gemini.
Operators can build, package, sign and publish malicious apps without leaving the console. Scheduled rebuilding produces fresh files while keeping the underlying implant unchanged, helping campaigns evade detection methods that depend on recognizing previously recorded file hashes.
Alongside remote control, the panel exposes stolen messages, credentials, contacts, photographs and files. Fake screens placed over targeted apps capture entered information.
Similar ToxicPanda wireless debugging abuse shows why this developer feature has become a concern beyond conventional credential theft.
A separate AI function analyzes collected SMS messages to estimate victims’ bank balances and rank devices by value. It helps operators select targets, rather than carrying out fraud itself.
Cleafy found no analyzed sample that used AI-guided navigation to complete a fraudulent transfer. Cleafy recommends monitoring activity executed as UID 2000, extending security checks beyond the application’s permissions and lifecycle.
Downloaded testing tools retain recognizable filenames in the temporary deployment directory, providing artifacts that investigators can examine during a suspected compromise.
The removal gap is important: deleting the visible app does not immediately stop the independent service, which survives until reboot. The research also warns that AI-assisted interface navigation could reduce the custom engineering needed for future automated banking attacks, although that broader capability was not demonstrated here.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.