The RatHat Android malware, known for its banking trojan capabilities, has evolved to use AI for identifying high-value targets. According to cybersecurity firm Cleafy, nearly 100 deployments of the malware’s web console have been traced since April 2026. This malware-as-a-service model allows each client to manage a distinct version, storing sensitive data like text messages and passwords from infected devices.
Utilizing Google’s Gemini AI, the latest console version estimates victims’ bank balances based on message content, categorizing them into high and mid-value targets. Cleafy emphasizes that, while the AI assesses value, it does not enact financial transactions, serving instead to prioritize targets for operators.
Evolution of the Malware Console
Since late 2025, the malware on victims’ phones has seen minimal changes, but its controlling console has been revamped. Initially connected to a console named Fisher, the system saw three new versions from April to September 2026. The first was termed BlackCat Remote Control Management, followed by Panda Workshop V5 and V6. Each version doubles as a build tool, allowing operators to create and deploy malware within seemingly benign apps.
These consoles can automate app rebuilding, generating new files to evade detection by security tools that identify known files through their hash values. Additionally, the latest version includes templates for deceptive download pages, such as one mimicking the Google Store.
Infiltration and Control Methods
Zimperium, another security firm, revealed the malware’s infiltration tactics, which involve text messages and online ads leading to third-party download sites. Once installed, the app requests Accessibility access, enabling it to read the screen and simulate user interactions. This access permits wireless debugging, connecting to the Android Debug Bridge (ADB) for deeper control.
With one click from the console, operators can deploy a Go-written program enabling persistent access through a reverse tunnel. This setup allows operators to bypass traditional screen capture prompts and record the screen using minicap and minitouch tools, although these are incompatible with Android 14 and later.
Widespread Deployment Insights
Cleafy’s investigations into console deployments reveal that nearly half of the observed IP addresses are linked to a Singapore-based network. The console’s limited user accounts suggest a lack of full trust in customers, possibly indicating a cautious approach by developers.
The initial console allowed AI provider selection and could send alerts when a victim’s AI score reached a threshold. The current version exclusively uses Gemini, directing operators to Google AI Studio for integration keys. The malware’s on-device AI interactions assist in maintaining wireless debugging, with Gemini providing tap instructions for unanticipated interfaces.
Cleafy and Zimperium’s reports include indicators for detecting the malware’s command-and-control servers and download links. They urge security tools to monitor processes running with shell user permissions, as these may indicate unauthorized activities.
As RatHat continues to exploit AI for sophisticated targeting, cybersecurity measures must adapt to counteract its evolving tactics, ensuring the protection of sensitive user data.
