RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
thehackernews.com Sep 29, 2026

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

AI-summarised brief · reviewed before publication

RatHat’s Android banking trojan is managed from a web console that now uses Google’s Gemini AI to rank victims by estimated bank balance, enabling operators to target high‑value phones. Cleafy identified nearly 100 console deployments since April 2026, each running a separate copy of the malware. The console builds, signs, and publishes the malicious app, auto‑rebuilds it hourly to evade hash‑based detection, and provides a Go‑based reverse‑tunnel for remote shell access. The malware exploits Accessibility permissions to capture screens and control the device without user prompts.

💡 Why It Matters

  • · By automating victim prioritization with AI, RatHat operators can focus resources on the most lucrative targets, raising the stakes for mobile banking security.
  • · The console’s continuous rebuilds and hidden deployment controls illustrate a sophisticated, scalable threat model that challenges existing detection and removal strategies.