Skip to main content
Emerging ThreatsMalware & Ransomware

RatHat Malware Evolves with AI-Powered Command Center

Server room with rows of equipment and a central console workstation.

Nearly 100 separate deployments since April 2026, Cleafy said — a tempo and variety that the company describes as consistent with a malware-as-a-service model.

Three C2 generations in six months and a name change

Cleafy reported that RatHat’s Android implant itself changed little between late 2025 and September 2026, but its command-and-control (C2) infrastructure evolved rapidly. Over a six‑month period the C2 panels moved through three distinct generations and rebranded from BlackCat to Panda Workshop. Those panel iterations, Cleafy said, show development activity and feature shifts occurring on the server side rather than inside the implant.

Panels that build, sign and rotate Android samples

The C2 consoles described by Cleafy are capable of producing, signing and publishing Android samples directly from the operator interface. Panels could regenerate samples on a schedule to produce fresh files — a technique intended to defeat hash‑based detection even while the underlying implant remained largely the same. Cleafy framed these capabilities as converting the C2 into a kind of “malware factory.”

Panda Workshop V5 and V6: access controls and phishing tools

Cleafy mapped feature differences across the Panda Workshop line. V5 added two‑factor authentication (2FA) for operators; V6 introduced a phishing download‑page builder and consolidated AI configuration around Google’s Gemini. Account limits and role‑based access controls observed in the panels, Cleafy said, were consistent with a commercial model in which customers operate their own RatHat instances — a structure that aligns with the nearly 100 distinct deployments seen since April 2026.

Wireless debugging, native services, and persistence outside app permissions

One operational capability Cleafy observed was the use of Android wireless debugging access from the panel to deploy a native Go service with a single click. That service provided shell‑level control outside the Android application permission model. Cleafy noted the service could survive removal of the malicious application and remain active until the next device reboot, granting operators a deeper and longer lived foothold than the app itself provided.

Gemini on the server and the device: AI for prioritization and UI assistance

Cleafy documented two separate uses of AI in the RatHat ecosystem. On the server side, Panda Workshop V6 used Google’s Gemini to analyze SMS messages already collected from infected phones and to estimate victims’ bank balances. The resulting scores sorted devices into “high‑value” and “mid‑value” groups, allowing operators to prioritize targets without manually reviewing every infected device; Cleafy emphasized the AI tool was used for victim prioritization, not to carry out fraud.

On the device side, the implant also used an LLM when static automation failed on unfamiliar Android interfaces: it sent screen details to an LLM and asked where to tap. Cleafy said earlier panels supported multiple AI providers, but V6 consolidated the configuration around Gemini. The company warned that the device‑side technique could revive automated transfer systems (ATS) that had been limited by the cost of scripting each banking app, though Cleafy observed that nothing in the samples performed a fraudulent transfer.

Campaign geography and deployment pattern

Cleafy reported parallel campaigns across Europe, Latin America and Southeast Asia. Nearly half of the observed IP addresses used by operators were located on a single Singapore‑based network, indicating a concentration of infrastructure despite the geographically dispersed operations. The firm’s count of almost 100 individual deployments since April 2026 underpinned its assessment that RatHat’s ecosystem behaves like a MaaS offering.

What this means for technologists, policymakers, and end users

  • Technologists and security teams: Cleafy’s findings point to C2‑side capabilities (automatic build/sign/publish, scheduled regeneration, role‑based accounts) that defenders should factor into detection and incident response playbooks; wireless debugging deployment of a native service suggests analysts should look beyond the app sandbox when assessing persistence.
  • Policymakers and regulators: The combination of commercialization features (account limits, role‑based access) and nearly 100 deployments supports Cleafy’s characterization of a MaaS model — a structure that may have implications for attribution, cross‑border enforcement and platform governance.
  • End users and organizations: The use of AI to triage infected devices and to assist device‑side automation underscores that mere detection of an app may not reflect the full extent of control; Cleafy’s note that device‑deployed services can persist until reboot highlights the importance of comprehensive remediation steps.

Cleafy’s analysis paints RatHat as a stable implant driven forward by an evolving, commercially oriented C2 ecosystem that automates both malware production and victim selection. The record in this report — rapid panel iteration, automation of sample generation, role‑based access and AI consolidation around Gemini — frames the immediate questions: how defenders detect server‑side churn, how operators leverage AI for scale, and which countermeasures will disrupt a C2 that functions as a factory. Read Cleafy’s full findings at the source link below.

https://www.infosecurity-magazine.com/news/rathat-c2-panel-malware-as-a/