// AI threat desk · 2 Oct 2026
Home/AI-ATK · AI-Powered Attacks
AI-Powered AttacksHighAGENT

RatHat Android Banking Trojan Console Uses Gemini to Pick High-Value Victims

Security firm Cleafy says the RatHat Android banking trojan control panel has logged nearly 100 deployments since April 2026. The latest version uses Google Gemini to estimate victims’ bank balances from text messages, sorting phones to help operators pick targets.

Illustration: mobile banking app interface
File photo: Illustration: mobile banking app interface. Photo: rawpixel (CC0)
Key takeaways
  • Cleafy tracked nearly 100 separate deployments of the RatHat control panel since April 2026, consistent with a ‘malware as a service’ model where each customer runs its own instance.
  • The latest version of the control panel supports only Google Gemini, which it uses to estimate victims’ bank balances from stolen text messages, sorting phones into ‘high value’ and ‘medium value’ groups.
  • The trojan itself also calls Gemini directly on the phone. When its built in tap commands fail on an unfamiliar phone interface, it lets the AI decide where on the screen to tap.
On this page

Three generations of control panels, little change to the trojan itself

According to Cleafy’s report, the RatHat Android banking trojan itself has changed little since late 2025. But the web control panel operators use to manage infected phones has been completely replaced, going through three generations in six months. Samples from late 2025 and February 2026 connected to an older panel called Fisher, while three new versions appeared between April and September 2026, named BlackCat Remote Control Management, Panda Workshop V5 and V6. All three share the same underlying code.

Each version also functions as a build tool. Operators can create a trojan within the panel, hide it inside a seemingly harmless app, sign it, and have the panel automatically publish it to Amazon S3 or a web server, with no need to handle hosting separately. The panel can also rebuild the app automatically on a schedule, for example every hour, generating a new file each time. This is aimed at defeating security tools that identify known malware by file hash.

Gemini used to estimate victims’ wealth and to help the trojan operate itself

The latest control panel supports only Google Gemini, and directs operators to Google AI Studio to obtain an API key. According to the report, the panel sends text message content collected by the trojan from victim phones to Gemini, which estimates the victim’s bank balance. Phones are then sorted into high value or medium value groups, letting operators prioritise more valuable targets. Cleafy found no evidence in the samples it analysed that the AI feature was used to directly transfer funds. Its role was limited to ‘deciding which victims are worth the operator’s time’.

The trojan itself also calls Gemini directly on the device. Because its built in tap commands are designed for specific phone brand interfaces, Android versions and languages, they fail on unforeseen devices. In that case, the trojan sends screen layout data to Gemini and taps the screen based on its instructions. The call is made directly from the phone using an API key stored in the trojan’s configuration. The Hacker News notes that another Android trojan called PromptSpy, described by security firm ESET in February this year, used the same technique of sending screen layouts to Gemini and following its tap instructions.

The trojan gains system level control via ADB

After installation, the app requests Accessibility permission, allowing it to read screen content and tap on the user’s behalf. The trojan uses this permission to enable wireless debugging itself, reads the pairing code shown on screen, and connects to the phone’s built in debugging tool, Android Debug Bridge (ADB). This gives it operating privileges as the Android system shell user (UID 2000), beyond what the app itself is normally granted.

Operators can launch a standalone program written in Go with one click from the control panel, maintaining control through a reverse channel, a connection initiated by the phone back to the operator’s server. This program uses tools called minicap and minitouch to stream the screen and simulate taps, without triggering permission prompts or showing a recording icon. However, both tools stop working on Android 14 and later. The Hacker News, citing analysis by security firm Zimperium, says this Go program keeps running even after the victim removes the app, until the phone restarts. It can also automatically reinstall the app and re-enable its Accessibility permission after deletion.

Nearly 100 deployments mostly linked to a single Singapore network

By searching control panel page titles and web code, Cleafy tracked nearly 100 separate panel deployments since April 2026, spread across Europe, Latin America and Southeast Asia. Nearly half of the observed IP addresses belonged to a single network registered in Singapore, AS4907. The report notes that the panel caps the number of operator accounts and hides certain features from non administrator users. This design only makes sense if users include customers the developer does not fully trust, that is, other criminal groups’ customers, consistent with a ‘malware as a service’ operating model.

What to do now

  1. Monitor for processes running on the phone as the shell user (UID 2000), Cleafy’s recommended detection focus.
  2. Check the device’s /data/local/tmp directory for the presence of minicap or minitouch files.
  3. Avoid installing apps from third party download sites or text message links. Install only from official app stores.
  4. Stay alert to apps requesting Accessibility permission, especially installation files from unknown sources.
  5. Banks and financial institutions can reference the domain and IP indicators listed in Cleafy’s report to block them at the network level.

FAQ

What is RatHat?

RatHat is an Android banking trojan spread via phishing text messages and malicious ads. It tricks users into downloading malware disguised as a normal app, then uses the Accessibility permission to gain control of the device.

What role does Gemini AI play in this attack?

Gemini is used in two ways. The control panel uses it to estimate victims’ bank balances from stolen text messages, filtering for high value targets. The trojan itself also calls Gemini to decide where to tap on screen when its built in tap commands fail. Cleafy says there is no evidence in the analysed samples that the AI was used to directly transfer funds.

Does removing the app mean a victim is safe?

Not necessarily. According to Zimperium’s analysis, the Go program deployed by operators can keep running after the app is removed, until the device restarts, and can automatically reinstall the app and re-enable its Accessibility permission.

Does ‘nearly 100 deployments’ mean nearly 100 infected phones?

No. Cleafy explicitly states this figure refers to the number of control panel (backend system) deployments it tracked, not the number of infected phones. The report does not say how many victims correspond to each deployment.

Sources

  1. From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat, Cleafy LabsPrimary
  2. New RatHat Android malware uses AI to automate device control, HKCERT
Explore with AI