RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

According to security firm Cleafy, the operators behind RatHat have developed a sophisticated Android banking trojan that enables them to control infected devices via a web console. Since April 2026, Cleafy has identified nearly 100 instances of this console in operation, indicating a malware-as-a-service model where each customer operates their own distinct version.

The console serves as a repository for data collected from compromised phones, including sensitive information such as text messages and passwords entered into counterfeit login screens that overlay genuine banking applications. The latest iteration of this malware even leverages Google’s Gemini AI model to assess each victim’s bank balance based on the extracted messages, categorizing the phones into high-value and mid-value segments. However, Cleafy notes that this AI functionality does not facilitate any financial transactions; rather, it assists operators in determining which targets warrant their attention.

One Console, Three Versions

While the malware itself has remained relatively unchanged since late 2025, the underlying console has undergone significant updates. Cleafy reports that samples from late 2025 and early 2026 were linked to an earlier console known as Fisher. Between April and September 2026, three new versions emerged, all derived from the same codebase. The first is dubbed BlackCat Remote Control Management, while the subsequent two are labeled Panda Workshop V5 and V6.

Each version functions not only as a control interface but also as a build tool. Operators can create the malware, embed it within seemingly innocuous applications, and publish the final product to platforms like Amazon S3 or other web servers without needing to manage the hosting environment directly. Furthermore, the console can automatically regenerate the app at specified intervals, creating new files to evade detection by security software that relies on file hashes.

The latest version also introduces templates for deceptive download pages, including one mimicking the Google Store, enhancing its ability to lure unsuspecting users.

Shell Access in One Click

RatHat infiltrates devices through text messages and online advertisements that redirect users to third-party download sites, as discovered by Zimperium earlier this month. Once installed, the application requests Accessibility access, granting it the ability to read the screen and simulate user interactions. This access enables the malware to activate wireless debugging, retrieve pairing codes, and connect to the Android Debug Bridge (ADB), a built-in debugging tool.

This connection provides the malware with a shell that operates with elevated privileges, allowing operators to execute commands with a single click. Cleafy has revealed that a deploy button initiates a separate Go program that remains accessible via a reverse tunnel established by the infected device.

While the ADB pairing occurs automatically, the Go program only activates upon the operator’s command. This program alters the method of screen monitoring, utilizing tools like minicap and minitouch to capture the screen and send touch commands without alerting the user, bypassing the usual permission prompts and recording icons. However, these tools are incompatible with Android 14 and later versions, leaving those devices reliant on the app’s native screen capture features.

Remarkably, the Go program persists even after the victim uninstalls the app, remaining active until the device is restarted. Zimperium has also noted that this program can reinstall the app post-deletion and re-enable its Accessibility access, complicating removal efforts.

How Widely the Console Is Used

Cleafy has tracked the console’s deployments by analyzing page titles and web code, counting instances of the console rather than the number of infected devices. The specifics of what constitutes a single deployment remain unspecified, and neither Cleafy nor Zimperium has provided exact victim counts.

The console imposes limits on operator accounts and conceals certain sections from non-administrative users, suggesting a lack of complete trust among its clientele. Notably, nearly half of the IP addresses identified by Cleafy originate from a Singapore-registered network.

Gemini on Both Ends

The initial version of the console allowed operators to choose from various AI providers, including the option to receive Telegram alerts when a phone’s AI score exceeded a predetermined threshold. The latest version, however, exclusively utilizes Gemini and directs operators to Google AI Studio for API key acquisition.

Interestingly, RatHat also employs Gemini on the infected devices. The malware’s built-in tap instructions are tailored for specific manufacturers’ interfaces, Android versions, and languages, which can lead to failures on unsupported devices. In such cases, the malware sends the screen layout to Gemini to determine the appropriate tap locations, directly invoking Gemini from the device using an API key embedded in its settings. Cleafy indicates that this feature is primarily used to maintain the wireless debugging setup.

Indicators and Detection

Cleafy has compiled a list of indicators associated with the consoles’ command-and-control servers, download links, and malware samples:

  • Domain: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
  • Domain: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
  • IP: 8.231.120[.]246 (C2 for BlackCat, April 2026)
  • Domain: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
  • URL: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
  • URL: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
  • MD5: 116346cace7f00ba557034b534d40791 (sample, September 2026)
  • MD5: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
  • MD5: f83357b2d47c7d38ee53943373961211 (sample, December 2025)

The consoles typically utilize web addresses that begin with “admin.” and often employ inexpensive top-level domains such as .best, .beer, and .top. Once the Go program is deployed, the minicap and minitouch files are stored in /data/local/tmp under their original names, making them detectable by scans. Cleafy advises that security tools should monitor processes running under the shell user (UID 2000) on affected devices. One of the domains listed, admin.xiongmaocs[.]pics, also appears in Zimperium’s earlier analysis, highlighting the interconnected nature of these threats.

AppWizard
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims