Android banking trojan RatHat is now using Google's Gemini to help its operators pick which victims to pursue, according to security firm Cleafy. The malware is sold as a service: Cleafy found nearly 100 deployments of its web console since April 2026, with each customer running a separate copy. The console stores data collected from infected phones, including text messages and passwords entered into fake banking login screens. In its latest version, it asks Gemini to estimate a victim's bank balance from those messages and sorts phones into high- and mid-value groups. Cleafy found no evidence the AI model is used to move money; its role, the company said, is "deciding which victims are worth an operator's time."
Cleafy says the console has been rebuilt several times. Earlier samples connected to a console named Fisher; three newer versions, in use between April and September 2026, are called BlackCat Remote Control Management and Panda Workshop V5 and V6. Every version doubles as a build tool: an operator can package the malware inside a harmless-looking app, sign it, and publish it to Amazon S3 or a web server without touching hosting. The console can also rebuild the app on a schedule, such as hourly, producing a new file each time to evade security tools that match known hashes. The latest version adds templates for fake download pages, including one labeled Google Store.
On the phone, RatHat abuses Android's Accessibility service to enable wireless debugging, read the pairing code, and connect through Android Debug Bridge, giving operators a one-click shell. A separate Go program, launched from the console and reached through a reverse tunnel, can stream the screen and send taps without a permission prompt on older Android versions; on Android 14 and later it falls back to the app's own screen capture. The Go program keeps running after the app is removed until the phone restarts, and can reinstall the app and re-enable Accessibility. Cleafy also found RatHat calling Gemini from the phone itself to interpret screen layouts when its preset tap instructions fail, a technique previously seen in the PromptSpy malware. The reports do not say how many phones were infected or provide complete removal steps.