RatHat Android Banking Trojan's Gemini-Powered MaaS Console Ranks Victims by Estimated Bank Balance
Cleafy traces nearly 100 deployments of the RatHat Android banking trojan's malware-as-a-service console since April 2026; the latest panel uses Google Gemini to estimate victims' bank balances from stolen SMS, prioritize high-value targets, and guide…
Cleafy research published September 28, 2026 details the RatHat Android banking trojan's command-and-control ecosystem, which has evolved into a malware-as-a-service operation with nearly 100 console deployments traced since April 2026 across Europe, Latin America, and Southeast Asia. The implant itself changed little from late 2025 through September 2026, while the C2 panel went through three generations in six months, spanning Fisher, BlackCat Remote Control Management, and Panda Workshop V5/V6 versions before rebranding from BlackCat to Panda Workshop. The console stores stolen SMS and passwords harvested via fake login overlays on banking apps, and its latest version uses Google's Gemini to analyze stolen SMS, estimate each victim's bank balance, and sort devices into high- and mid-value groups. Almost half of observed IPs sat on one Singapore-based network. On-device, the trojan abuses Accessibility access to enable wireless debugging and pair with ADB, yielding a shell running as UID 2000, while a native Go program maintains a reverse tunnel and streams the screen via minicap/minitouch without permission prompts, operating outside Android's permission model. The two reports describe persistence differently: The Hacker News says the Go payload persists after app removal, reinstalls the malware, and restores Accessibility access, while Infosecurity Magazine says the Go service persists until reboot. When built-in instructions fail, the malware sends screen layouts to Gemini for tap guidance, which Cleafy notes mirrors ESET's PromptSpy findings from February. The panels build, sign, and regenerate samples to evade hash-based detection — The Hacker News specifies the console rebuilds the APK hourly and hosts it on Amazon S3.
- Cleafy research published September 28, 2026; nearly 100 malware-as-a-service console deployments traced since April 2026
- Campaigns observed across Europe, Latin America, and Southeast Asia; almost half of observed IPs sat on one Singapore-based network
- Console lineage: Fisher, BlackCat Remote Control Management, and Panda Workshop V5/V6; three panel generations in six months; rebranded from BlackCat to Panda Workshop
- RatHat implant changed little from late 2025 through September 2026, while the C2 panel evolved rapidly
- Latest panel uses Google Gemini to analyze stolen SMS, estimate victims' bank balances, and sort devices into high- and mid-value groups
- Credentials harvested via fake login overlays on banking apps; stolen SMS and passwords stored in the console
- Accessibility abuse enables wireless debugging and ADB pairing, yielding a shell running as UID 2000 outside Android's permission model
- Go program maintains a reverse tunnel and streams the screen via minicap/minitouch without permission prompts
Coverage timelineoldest first · each row is one article
- · 1d agoRatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
The Hacker News· 60
Cleafy details RatHat Android banking trojan's malware-as-a-service console, which uses Google Gemini to rank victims by bank balance and guide on-device taps.
- · 13h agoRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
Infosecurity Magazine· 55
Cleafy details RatHat Android banking trojan's C2 panel evolving into a Gemini-powered malware-as-a-service platform that ranks victims by estimated bank balance.