Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
RatHat Android Malware Uses AI for Victim Targeting

RatHat Android Malware Uses AI for Victim Targeting

Posted on September 28, 2026 By CWS

The RatHat Android malware, known for its banking trojan capabilities, has evolved to use AI for identifying high-value targets. According to cybersecurity firm Cleafy, nearly 100 deployments of the malware’s web console have been traced since April 2026. This malware-as-a-service model allows each client to manage a distinct version, storing sensitive data like text messages and passwords from infected devices.

Utilizing Google’s Gemini AI, the latest console version estimates victims’ bank balances based on message content, categorizing them into high and mid-value targets. Cleafy emphasizes that, while the AI assesses value, it does not enact financial transactions, serving instead to prioritize targets for operators.

Evolution of the Malware Console

Since late 2025, the malware on victims’ phones has seen minimal changes, but its controlling console has been revamped. Initially connected to a console named Fisher, the system saw three new versions from April to September 2026. The first was termed BlackCat Remote Control Management, followed by Panda Workshop V5 and V6. Each version doubles as a build tool, allowing operators to create and deploy malware within seemingly benign apps.

These consoles can automate app rebuilding, generating new files to evade detection by security tools that identify known files through their hash values. Additionally, the latest version includes templates for deceptive download pages, such as one mimicking the Google Store.

Infiltration and Control Methods

Zimperium, another security firm, revealed the malware’s infiltration tactics, which involve text messages and online ads leading to third-party download sites. Once installed, the app requests Accessibility access, enabling it to read the screen and simulate user interactions. This access permits wireless debugging, connecting to the Android Debug Bridge (ADB) for deeper control.

With one click from the console, operators can deploy a Go-written program enabling persistent access through a reverse tunnel. This setup allows operators to bypass traditional screen capture prompts and record the screen using minicap and minitouch tools, although these are incompatible with Android 14 and later.

Widespread Deployment Insights

Cleafy’s investigations into console deployments reveal that nearly half of the observed IP addresses are linked to a Singapore-based network. The console’s limited user accounts suggest a lack of full trust in customers, possibly indicating a cautious approach by developers.

The initial console allowed AI provider selection and could send alerts when a victim’s AI score reached a threshold. The current version exclusively uses Gemini, directing operators to Google AI Studio for integration keys. The malware’s on-device AI interactions assist in maintaining wireless debugging, with Gemini providing tap instructions for unanticipated interfaces.

Cleafy and Zimperium’s reports include indicators for detecting the malware’s command-and-control servers and download links. They urge security tools to monitor processes running with shell user permissions, as these may indicate unauthorized activities.

As RatHat continues to exploit AI for sophisticated targeting, cybersecurity measures must adapt to counteract its evolving tactics, ensuring the protection of sensitive user data.

The Hacker News Tags:AI, Android, banking trojan, Cleafy, Cybersecurity, Gemini AI, Malware, RatHat, Security, Zimperium

Post navigation

Previous Post: Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
Next Post: Microsoft SharePoint Vulnerability Heightens Security Risks

Related Posts

LofyGang Returns with Minecraft Malware Campaign LofyGang Returns with Minecraft Malware Campaign The Hacker News
Rethinking Security for Scattered Spider Rethinking Security for Scattered Spider The Hacker News
Google Ordered to Pay 4M for Misusing Android Users’ Cellular Data Without Permission Google Ordered to Pay $314M for Misusing Android Users’ Cellular Data Without Permission The Hacker News
CISA Highlights Critical Linux Vulnerability Exploitation CISA Highlights Critical Linux Vulnerability Exploitation The Hacker News
Fake IT Support Scam Spreads Havoc C2 Framework Fake IT Support Scam Spreads Havoc C2 Framework The Hacker News
Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft SharePoint Vulnerability Heightens Security Risks
  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access
  • OpenCode Vulnerability Risks Unauthorized Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft SharePoint Vulnerability Heightens Security Risks
  • RatHat Android Malware Uses AI for Victim Targeting
  • Oracle PeopleSoft Vulnerability Exploited by ShinyHunters
  • NeedyMantis Malware Ensures Long-Term Network Access
  • OpenCode Vulnerability Risks Unauthorized Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark