VMTech
Discuss a project →

RatHat Console Uses Gemini to Prioritize Android Banking Trojan Victims

RatHat Console Uses Gemini to Prioritize Android Banking Trojan Victims

Security company Cleafy has identified nearly 100 deployments of the RatHat Android malware management console since April 2026. The latest console, Panda Workshop V6, uses Google’s Gemini model to estimate a victim’s bank balance from text messages stolen by the banking trojan and group compromised devices into high-value and mid-value categories.

Cleafy said the capability is intended to determine which victims deserve an operator’s attention. In the samples it examined, Gemini was not used to initiate or automate money transfers. RatHat’s operators build and distribute the Android banking trojan through a web console that stores collected messages and credentials entered into fake banking-login overlays.

A malware-as-a-service console with changing versions

The researchers said RatHat’s malware on infected devices has changed little since late 2025, but the supporting console has been replaced. Samples from late 2025 and February 2026 communicated with an earlier console called Fisher. Between April and September 2026, Cleafy observed three new versions built from shared code: BlackCat Remote Control Management, Panda Workshop V5 and Panda Workshop V6.

Each version doubles as a build system. An operator can create the malware, conceal it in an apparently harmless application, sign the resulting app and publish it to Amazon S3 or a web server without directly configuring hosting. The consoles can also rebuild an application on a schedule, including every hour. Each rebuild produces a new file from the same malware, a technique Cleafy linked to attempts to bypass tools that identify known files by hash.

The latest version also includes templates for counterfeit download pages, including one labelled Google Store. Cleafy’s deployment figure represents observed console installations, not the number of infected phones. It found the systems by searching page titles and web code, and said its observations fit a malware-as-a-service model in which customers operate separate console copies.

ADB access expands device control

Zimperium found that RatHat reaches devices through text messages and online advertising that direct victims to third-party download sites. Once installed, the application requests Android Accessibility access. With that permission, it can read the screen and act on the user’s behalf, enable wireless debugging, read the displayed pairing code and connect to Android Debug Bridge.

This gives the malware access to a shell running as Android’s shell user, UID 2000, outside the app’s ordinary permission set. Cleafy found that an operator can access that shell from the console with a single click. A deploy action starts a separate Go program that remains reachable through a reverse tunnel opened by the phone to the operator’s infrastructure.

The Go component can use minicap and minitouch to stream the screen and send taps without the permission prompt and recording icon associated with Android’s app-level screen capture. Cleafy said those tools do not function on Android 14 and later, where the malware must use its own screen-capture function and associated prompt. The component can continue running after the victim deletes the app until the device restarts; Zimperium also found that it can reinstall the app and re-enable Accessibility access.

Gemini appears in operator and device workflows

Earlier console code supported several AI providers and could send a Telegram alert when a device score exceeded a configured threshold. Panda Workshop V6 uses only Gemini and directs operators to Google AI Studio for an API key. RatHat also calls Gemini from the compromised device when its built-in instructions for navigating manufacturer-specific Android interfaces fail. It sends the screen layout to the model and requests directions on where to tap to preserve wireless-debugging setup.

Cleafy advised defenders to monitor processes operating as UID 2000 and to scan for minicap and minitouch in /data/local/tmp after the Go program is deployed. For businesses, the practical implication is to investigate unexpected Accessibility requests, wireless-debugging changes and shell-user activity as connected mobile compromise signals, rather than depending only on file-hash detection.

#androidsecurity#malwareanalysis#mobilethreats#cybersecurity
Open analytics
On the site 0 views
min read 5 28.09.2026
Instagram

RatHat Console Uses Gemini to Prioritize Android Banking Trojan Victims

Open the post on Instagram ↗