← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

RatHat Android Malware Console Uses Google Gemini to Prioritize Victims

🔄 Updated 3d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • RatHat malware console uses Google Gemini AI.
  • Gemini analyzes text messages to estimate bank balances.
  • Victims are sorted into high-value and mid-value groups.
  • The console also acts as a build and publishing tool.
  • Malware gains shell access via Android Debug Bridge (ADB).

Gemini AI Integration for Victim Prioritization

Security company Cleafy reports that the latest version of the RatHat Android banking trojan's control console now incorporates Google's Gemini AI model. This integration allows the malware operators to analyze text messages collected from infected phones to estimate victims' bank balances. The system then categorizes victims into "high-value" and "mid-value" groups, enabling operators to focus their efforts on more lucrative targets.

Malware-as-a-Service Model

Cleafy has identified nearly 100 deployments of the RatHat console since April 2026, indicating a malware-as-a-service (MaaS) model where different customers operate separate instances. The console stores data collected by the malware, including text messages and credentials from fake login screens overlaid on banking applications. While Gemini is used for victim assessment, Cleafy found no evidence of it being used to directly move money.

Console Evolution and Features

Although the on-device malware has remained largely consistent since late 2025, the control console has undergone several updates. Earlier versions connected to a console named Fisher, while three new versions, including BlackCat Remote Control Management and Panda Workshop V5 and V6, emerged between April and September 2026. These consoles function as build tools, allowing operators to create, hide, and sign malware within seemingly harmless apps, then publish them to Amazon S3 or web servers. The console can also schedule app rebuilds to evade hash-based security detection, and the latest version includes templates for fake download pages.

Gaining Device Control

RatHat malware typically infects phones via text messages and online ads leading to third-party download sites. Once installed, it requests Accessibility access, which it then uses to enable wireless debugging and connect to the phone's Android Debug Bridge (ADB). This grants the malware shell access running as Android's shell user (UID 2000), bypassing typical app permissions and allowing operators to control the device with a single click from the console.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub Zimperium/IOC

Reporting from

The RatHat Android banking trojan's latest console version integrates Google's Gemini AI to analyze victim text messages and estimate bank balances, sorting victims into high-value and mid-value groups. This allows operators to prioritize their efforts, indicating a shift in malware-as-a-service tactics towards more efficient victim targeting.