Skip to main content
Emerging ThreatsMalware & Ransomware

RatHat Malware Leverages Gemini to Target High-Value Android Victims

Smartphone sits on park bench with blurred screen, surrounded by city street and pedestrians.

Cleafy has traced nearly 100 deployments of an Android-banking-trojan control console since April 2026, and the console now asks Google's Gemini model to rank victims by likely bank balance, the security company reported.

Cleafy’s findings and the malware-as-a-service model

Security company Cleafy analyzed the RatHat ecosystem and concluded that the console behind the Android banking trojan fits a malware-as-a-service model: the developers build and publish a web console that customers run as separate copies. The console stores what the malware collects from each phone — including text messages and passwords captured by fake login screens overlaid on banking apps — and the latest console asks Google's Gemini AI to estimate each victim's bank balance and sort infected phones into "high-value" and "mid-value" groups.

That AI-driven sorting is not used to transfer funds, Cleafy emphasized: Gemini's role is "deciding which victims are worth an operator's time," the company said.

One console, three versions: Fisher, BlackCat, Panda Workshop V5/V6

Cleafy traced continuity and change across the infrastructure. Malware samples from late 2025 and February 2026 connected to an earlier console named Fisher. Between April and September 2026 Cleafy observed three new consoles built from the same code: first a BlackCat Remote Control Management instance, then Panda Workshop V5 and V6.

Each console also functions as a build tool. Operators can build the malware from the console, hide it inside a seemingly harmless app, sign it, and publish the finished APK to Amazon S3 or a web server without touching the hosting. Consoles can rebuild apps on a schedule — for example, hourly — producing new files that evade hash-based detection. The latest console adds fake-download-page templates, including one labeled "Google Store."

How RatHat gains shell access and persists on devices

RatHat reaches phones through SMS messages and online ads leading to third-party download sites, Zimperium reported earlier in September 2026; once installed, the app requests Android Accessibility access. With that permission the app enables wireless debugging, reads the pairing code from the screen, and connects to Android Debug Bridge (ADB). That gives the attackers a shell running as Android's shell user (UID 2000), outside the app's normal permissions.

From the console, a single "deploy" button starts a separate Go program that the phone reaches back to the operator through a reverse tunnel. That Go program uses minicap and minitouch to stream the screen and inject taps without the system permission prompts or a recording icon. Cleafy noted those two tools do not work on Android 14 and later; in such cases the app's built-in screen-capture path — which shows a permission prompt and recording icon — remains the available option. Cleafy also described a lower-frame-rate backup using screencap but did not specify applicable Android versions.

Zimperium found the Go program can persist after the app is removed, remaining active until the phone restarts; it can also reinstall the app and re-enable Accessibility access. Neither Cleafy nor Zimperium provided steps for complete removal.

Gemini on the server and on the phone

Gemini figures in two places. The latest console version works only with Gemini and directs operators to Google AI Studio to obtain an API key; earlier console builds let operators pick among multiple AI providers and could send Telegram alerts when an AI score passed a threshold. On the phone itself, RatHat uses Gemini for on-device assistance when built-in tap instructions fail: the malware sends a screen layout to Gemini and asks where to tap, calling Gemini directly from the infected device using an API key stored in the app's settings.

Cleafy observed the on-device Gemini feature is used to keep the wireless-debugging setup operational. Cleafy also noted a precedent: PromptSpy, described by ESET in February, similarly sent screen layouts to Gemini and followed its tap instructions.

Indicators, detection points, and hosting patterns

Cleafy published concrete indicators for hunt-and-detection efforts, including domains, an IP address, URLs, and sample MD5s:

  • Domain: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
  • Domain: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
  • IP: 8.231.120[.]246 (C2 for BlackCat, April 2026)
  • Domain: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
  • URL: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
  • URL: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
  • MD5: 116346cace7f00ba557034b534d40791 (sample, September 2026)
  • MD5: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
  • MD5: f83357b2d47c7d38ee53943373961211 (sample, December 2025)

Cleafy noted the consoles typically use cheap top-level domains and web addresses beginning with admin. and adminapi. for back ends. Nearly half of the IP addresses Cleafy observed are on a single Singapore-registered network, AS4907. Once the Go program is deployed, minicap and minitouch binaries sit under /data/local/tmp with their real names — a location Cleafy recommends scanning — and Cleafy advised monitoring processes running as UID 2000.

What this means for security teams, end users, and operators

Security teams: Cleafy's record points to immediate, specific detection priorities — hunt for admin.* domains and the listed URLs and MD5s; monitor for minicap/minitouch in /data/local/tmp; and watch for processes running as UID 2000. The console's ability to rebuild binaries frequently argues for behavioral detection rather than reliance on file hashes alone.

End users: the campaign spreads through text messages and ads that lead to third-party download sites and fake download pages (including templates labeled "Google Store"); apps requesting Accessibility access are central to the attack chain. The reports indicate extra caution with third-party APKs and attention to unexpected Accessibility prompts.

Operators and buyers of the consoles: the infrastructure limits operator accounts and hides sections from non-admins, an architecture consistent with a service model in which customers are not fully trusted by the developers. Consoles offer built-in hosting to Amazon S3 or arbitrary web servers and can rebuild and republish payloads on a schedule, reducing the friction for customers to run independent instances.

The record compiled by Cleafy and Zimperium maps an ecosystem that automates both malware production and victim triage: nearly 100 console deployments by September 2026, server-side and on-device uses of Gemini for ranking and control, and toolchains that grant shell access and persistence. The immediate question left on the table in the published material is whether AI's role will remain limited to triage and reliability fixes or grow into new functions for operators — a trajectory the evidence so far shows is being actively explored.

Source: The Hacker News — RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims