thehackernews.com
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat’s Android banking trojan is managed from a web console that now uses Google’s Gemini AI to rank victims by estimated bank balance, enabling operators to target high‑value phones. Cleafy identified nearly 100 console deployments since April 2026, each running a separate copy of the malware. The console builds, signs, and publishes the malicious app, auto‑rebuilds it hourly to evade hash‑based detection, and provides a Go‑based reverse‑tunnel for remote shell access. The malware exploits Accessibility permissions to [...]