Nearly 100 separate deployments since April 2026, Cleafy said — a tempo and variety that the company describes as consistent with a malware-as-a-service model.
Three C2 generations in six months and a name change
Cleafy reported that RatHat’s Android implant itself changed little between late 2025 and September 2026, but its command-and-control (C2) infrastructure evolved rapidly. Over a six‑month period the C2 panels moved through three distinct generations and rebranded from BlackCat to Panda Workshop. Those panel iterations, Cleafy said, show development activity and feature shifts occurring on the server side rather than inside the implant.
Panels that build, sign and rotate Android samples
The C2 consoles described by Cleafy are capable of producing, signing and publishing Android samples directly from the operator interface. Panels could regenerate samples on a schedule to produce fresh files — a technique intended to defeat hash‑based detection even while the underlying implant remained largely the same. Cleafy framed these capabilities as converting the C2 into a kind of “malware factory.”

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coveragePanda Workshop V5 and V6: access controls and phishing tools
Cleafy mapped feature differences across the Panda Workshop line. V5 added two‑factor authentication (2FA) for operators; V6 introduced a phishing download‑page builder and consolidated AI configuration around Google’s Gemini. Account limits and role‑based access controls observed in the panels, Cleafy said, were consistent with a commercial model in which customers operate their own RatHat instances — a structure that aligns with the nearly 100 distinct deployments seen since April 2026.
Wireless debugging, native services, and persistence outside app permissions
One operational capability Cleafy observed was the use of Android wireless debugging access from the panel to deploy a native Go service with a single click. That service provided shell‑level control outside the Android application permission model. Cleafy noted the service could survive removal of the malicious application and remain active until the next device reboot, granting operators a deeper and longer lived foothold than the app itself provided.
Gemini on the server and the device: AI for prioritization and UI assistance
Cleafy documented two separate uses of AI in the RatHat ecosystem. On the server side, Panda Workshop V6 used Google’s Gemini to analyze SMS messages already collected from infected phones and to estimate victims’ bank balances. The resulting scores sorted devices into “high‑value” and “mid‑value” groups, allowing operators to prioritize targets without manually reviewing every infected device; Cleafy emphasized the AI tool was used for victim prioritization, not to carry out fraud.
On the device side, the implant also used an LLM when static automation failed on unfamiliar Android interfaces: it sent screen details to an LLM and asked where to tap. Cleafy said earlier panels supported multiple AI providers, but V6 consolidated the configuration around Gemini. The company warned that the device‑side technique could revive automated transfer systems (ATS) that had been limited by the cost of scripting each banking app, though Cleafy observed that nothing in the samples performed a fraudulent transfer.
Campaign geography and deployment pattern
Cleafy reported parallel campaigns across Europe, Latin America and Southeast Asia. Nearly half of the observed IP addresses used by operators were located on a single Singapore‑based network, indicating a concentration of infrastructure despite the geographically dispersed operations. The firm’s count of almost 100 individual deployments since April 2026 underpinned its assessment that RatHat’s ecosystem behaves like a MaaS offering.
What this means for technologists, policymakers, and end users
- Technologists and security teams: Cleafy’s findings point to C2‑side capabilities (automatic build/sign/publish, scheduled regeneration, role‑based accounts) that defenders should factor into detection and incident response playbooks; wireless debugging deployment of a native service suggests analysts should look beyond the app sandbox when assessing persistence.
- Policymakers and regulators: The combination of commercialization features (account limits, role‑based access) and nearly 100 deployments supports Cleafy’s characterization of a MaaS model — a structure that may have implications for attribution, cross‑border enforcement and platform governance.
- End users and organizations: The use of AI to triage infected devices and to assist device‑side automation underscores that mere detection of an app may not reflect the full extent of control; Cleafy’s note that device‑deployed services can persist until reboot highlights the importance of comprehensive remediation steps.
Cleafy’s analysis paints RatHat as a stable implant driven forward by an evolving, commercially oriented C2 ecosystem that automates both malware production and victim selection. The record in this report — rapid panel iteration, automation of sample generation, role‑based access and AI consolidation around Gemini — frames the immediate questions: how defenders detect server‑side churn, how operators leverage AI for scale, and which countermeasures will disrupt a C2 that functions as a factory. Read Cleafy’s full findings at the source link below.
https://www.infosecurity-magazine.com/news/rathat-c2-panel-malware-as-a/




