Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
September 28, 2026 — Independent research from Cleafy and Zimperium published today details the evolution of RatHat: an Android banking trojan distributed as malware-as-a-service that integrates Google's generative AI model Gemini not to steal money directly, but to calculate which victims warrant manual operator intervention. The novelty lies not in AI's use in cybercrime, but in the economic tier of the delegated decision: from simple automation to net-worth estimation and strategic triage.
- Nearly 100 RatHat console deployments have been tracked by Cleafy since April 2026, in a MaaS model with separate copies for each customer.
- Gemini analyzes victim SMS messages to estimate bank balances and sort devices into high-value and mid-value groups, prioritizing operator attention.
- Persistence is achieved through ADB wireless self-pairing with escalation to a UID 2000 shell, deployment of a Go Agent with an FRP reverse tunnel, and automatic reinstallation capability post-uninstallation.
- Zimperium attributes the operation to China-based threat actors and documents four specific anti-analysis techniques: container tampering, manifest bomb, DEX bytecode poisoning, and dual string-encryption.
From "Spray and Pray" to LLM-Driven Economic Targeting
RatHat has existed since at least late 2025, when Cleafy identified the first console version, dubbed Fisher, and the first associated malware sample. A second sample linked to the same console appeared in February 2026; large-scale distribution of the next version, BlackCat Remote Control Management, began in April. Since then, Cleafy has tracked nearly 100 console deployments, with two further updates: Panda Workshop V5 in August and Panda Workshop V6 in September.
The qualitative differentiator in this campaign is the integration of Gemini into back-end operations. The console collects SMS messages extracted from infected devices — many containing banking notifications, transaction alerts, and OTP codes — and submits them to the generative model for analysis. According to Cleafy, "the latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups." The objective, as the same source notes, is to "decide which victims deserve the operator's time." Gemini does not execute transfers, generate payment commands, or interact with banking APIs; it produces an economic-value estimate to optimize the allocation of human criminal resources.
This mechanism transforms the attack's cost-benefit ratio. In a classic banking trojan model, the operator must manually intervene on every device with no profit guarantee. With RatHat, selection occurs upstream: the LLM acts as an economic filter, reducing time spent on victims with low extraction potential. It is an application of generative AI to criminal logistics, not to the technical execution of theft.
How the Malware Compromises and Retains the Device
The infection chain begins with fraudulent SMS messages and online ads directing users to third-party download sites. Once installed, the malicious APK requests Accessibility Services access under the pretense of enabling support features. From this privileged position, it enables wireless debugging, reads the ADB pairing code, and establishes a connection with the device itself.
The ADB connection provides a shell with shell user privileges (UID 2000), outside the original application's sandbox. Through this channel, a Go program — disguised as the native library 'liblocal-service.so' according to Zimperium — is deployed, establishing a persistent reverse tunnel via FRP (Fast Reverse Proxy). The Go Agent includes a hardware-level keylogger and uses minicap and minitouch for screen streaming and synthetic tap execution, both without requiring user-visible permissions and without generating Android's standard screen-recording icon.
On Android 14 and later, minicap and minitouch do not function; the malware falls back to an alternative screencap method at roughly 5 fps, less stealthy but functionally equivalent. Persistence is particularly aggressive: the Go program survives the original app's uninstallation, can reinstall it, and restore Accessibility permissions, maintaining control until device reboot.
Nearly half of the command-and-control IP addresses observed by Cleafy reside on AS4907, registered in Singapore. Infrastructure geography does not necessarily match operator geography: Zimperium assessed that RatHat is operated by China-based threat actors, but the dossier provides no further details on the group's identity.
"The malware serializes the device's live Accessibility tree into XML and communicates with one of the world's most popular generative AI assistants"
— Zimperium, via The Hacker News
Gemini's Dual Role: Back-End and Device
Gemini integration operates on two distinct levels. On the server, as described, batch SMS analysis and economic victim scoring occur. On the device, Gemini serves as a fallback mechanism for UI navigation: when hardcoded tap instructions in the malware fail to recognize a specific banking app's layout, the malware serializes the accessibility tree into XML, sends it to Gemini, and receives tap coordinates to continue the interaction. Zimperium specifies the response is structured in JSON with the named target's center coordinates, used to direct synthetic clicks.
This runtime LLM use is circumscribed: according to Cleafy, on-device Gemini is limited to maintaining the wireless debugging configuration, while the economic triage logic resides in the console. The architectural separation reflects modular design: the on-phone malware has remained substantially unchanged since late 2025, while the console has been completely reimplemented three times in six months.
A notable technical detail: the first console version supported multiple generative model providers; the latest uses Gemini exclusively and directs operators to Google AI Studio for API key provisioning. Dependence on a single legitimate AI ecosystem — with which criminal operators interact through ordinary accounts — introduces a complex governance vector on which the sources offer no assessment.
Anti-Analysis and Multi-Tier Architecture
Zimperium has documented four specific anti-analysis techniques in the RatHat sample. Container tampering alters the APK file structure to prevent opening with standard tools. The manifest bomb inserts data into AndroidManifest.xml designed to exceed common parser limits. DEX bytecode poisoning selectively corrupts Dalvik bytecode to evade decompilation. Dual string-encryption applies two encryption layers to sensitive strings, complicating static indicator extraction.
The overall architecture, as Zimperium describes it, comprises three main components: the malicious Android application, the Go Agent, and the FRP reverse-proxy client. Each console version also functions as a build tool: it automatically compiles, signs, and publishes the APK to designated Amazon S3 buckets or web servers. The console can recompile the application at intervals — Cleafy cites "every hour" as an example — generating new hashes to evade signature-based detection systems.
Recommended Actions
For financial institutions, the priority is recognizing that banking trojans have moved beyond simple automation and now employ LLMs for strategic economic decisions. This requires:
- Reviewing transaction detection models: an attack preceded by economic triage will show higher success rates on selected accounts, making uniform statistical thresholds less effective. \li>Monitoring anomalous Accessibility Services usage on customer devices, particularly coinciding with ADB wireless debugging activation.\li>Advising customers that no legitimate banking institution requires Accessibility Services or wireless debugging activation for ordinary operations.\li>Ensuring threat intelligence feeds include RatHat-specific IoCs: C2 domains, download URLs, and MD5 hashes documented by Cleafy, with attention to the rapid rotation driven by the hourly recompilation mechanism.
Why This Changes the Risk Calculus
RatHat does not represent a traditional technological leap: Accessibility Services abuse, ADB persistence, and even LLM integration in Android malware were previously documented techniques — PromptSpy, analyzed by ESET in February 2026, was the first known case. The qualitative difference lies in the economics of the decision. When an LLM estimates bank balances to optimize human intervention, the malware ceases to be a tool and becomes a criminal capital allocation system.
For financial institutions, this means facing adversaries who select their customers with the same logic — if not the same tools — as a wealth manager. For mobile security vendors, as Zimperium notes, "RatHat's multi-tier architecture, reliance on daemons outside the official lifecycle, and use of real-time GenAI decision loops illustrate why traditional signature-based mobile security controls are insufficient."
The dossier does not specify the exact number of infected devices, victim geography, the exact Gemini model employed, or the MaaS service cost for buyers. No infrastructure overlaps linking RatHat to other known criminal groups have emerged to date. The source does not document specific remediation measures for complete malware removal from compromised devices.
Information verified against cited sources and current as of publication.
Sources
- https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
- https://www.infosecurity-magazine.com/news/banking-trojan-remote-control/
- https://blog.netmanageit.com/rathat-android-malware-console-uses-gemini-to-identify-higher-value-victims/
- https://news.cybertechworld.co.in/index.php/2026/09/28/rathat-android-malware-console-uses-gemini-to-identify-higher-value-victims/
- https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
- https://thehackernews.com/2026/02/promptspy-android-malware-abuses-google.html
- https://thehackernews.uk/enterprise-ai-security-a
- https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html?ref=blog.netmanageit.com
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.