Security company Cleafy reports that the latest version of the RatHat Android banking trojan's control console now incorporates Google's Gemini AI model. This integration allows the malware operators to analyze text messages collected from infected phones to estimate victims' bank balances. The system then categorizes victims into "high-value" and "mid-value" groups, enabling operators to focus their efforts on more lucrative targets.
Cleafy has identified nearly 100 deployments of the RatHat console since April 2026, indicating a malware-as-a-service (MaaS) model where different customers operate separate instances. The console stores data collected by the malware, including text messages and credentials from fake login screens overlaid on banking applications. While Gemini is used for victim assessment, Cleafy found no evidence of it being used to directly move money.
Although the on-device malware has remained largely consistent since late 2025, the control console has undergone several updates. Earlier versions connected to a console named Fisher, while three new versions, including BlackCat Remote Control Management and Panda Workshop V5 and V6, emerged between April and September 2026. These consoles function as build tools, allowing operators to create, hide, and sign malware within seemingly harmless apps, then publish them to Amazon S3 or web servers. The console can also schedule app rebuilds to evade hash-based security detection, and the latest version includes templates for fake download pages.
RatHat malware typically infects phones via text messages and online ads leading to third-party download sites. Once installed, it requests Accessibility access, which it then uses to enable wireless debugging and connect to the phone's Android Debug Bridge (ADB). This grants the malware shell access running as Android's shell user (UID 2000), bypassing typical app permissions and allowing operators to control the device with a single click from the console.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The RatHat Android banking trojan's latest console version integrates Google's Gemini AI to analyze victim text messages and estimate bank balances, sorting victims into high-value and mid-value groups. This allows operators to prioritize their efforts, indicating a shift in malware-as-a-service tactics towards more efficient victim targeting.