
Android Malware RatHat Uses Gemini AI to Rank Victim Bank Balance
RatHat banking trojan's console uses Google Gemini to estimate victim bank balances from SMS, grouping phones by value for targeted attacks.
The Android banking trojan known as RatHat now employs Google's Gemini AI model to sort infected phones by how much money they are likely worth, according to new research from security company Cleafy. The malware's web console, used by its operators to manage victims, analyzes stolen text messages with Gemini to estimate the bank balance of each phone and then groups them into high-value and mid-value tiers, letting attackers focus their effort where the largest payouts are.
Cleafy traced nearly 100 deployments of the RatHat console since April 2026, and the company says the operation fits a malware-as-a-service pattern: each customer runs their own copy of the console, which stores everything that the malware gathers from compromised phones, including SMS messages and passwords entered into fake login screens that overlay real banking apps. While earlier versions let operators choose from several AI providers, the latest release works only with Gemini and directs users to obtain an API key from Google AI Studio. The AI is not used to move money, Cleafy notes; its job is "deciding which victims are worth an operator's time."
The malware on victims' phones has changed little since late 2025, but the console behind it has been completely overhauled. Samples from late 2025 and February 2026 communicated with an earlier console called Fisher. Between April and September 2026, three new versions appeared, all built from the same code: first a version named BlackCat Remote Control Management, then Panda Workshop V5 and Panda Workshop V6. Beyond managing victims, every console version doubles as a build tool. An operator can assemble the malware, hide it inside a harmless-looking app, sign it, and then publish the finished package to Amazon S3 or a web server without ever touching the hosting setup. The console can also rebuild the app on a schedule, such as every hour, creating a new file from the same malicious code to evade security tools that block known files by their unique digital fingerprints.
RatHat reaches phones through text messages and online ads that lead to third-party download sites, as Zimperium reported earlier this month. Once installed, the app requests Accessibility access, an Android permission that allows an app to read the screen and tap on behalf of the user. With this granted, the malware enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a built-in developer tool. This gives the malware a shell, a command-line interface that runs with elevated system privileges, outside the normal restrictions of installed apps. From the console, an operator can activate this shell with a single click. A deploy button starts a separate program written in the Go programming language, which stays reachable through a reverse tunnel, a connection the phone opens outward to the attacker's server. This pairing with ADB happens automatically in the background; the Go program launches only after the operator clicks deploy.
That Go program changes how the operator can watch the screen. The app's own screen capture uses a standard Android feature that pops up a permission prompt and shows a recording icon, which could alert a victim. The Go program instead uses tools called minicap and minitouch to stream the screen and send taps with no permission prompt and no visible recording icon. However, these tools do not work on Android 14 and later, so on those devices the malware falls back to the app's own screen capture with its telltale icon. Cleafy also described a backup method that uses a tool called screencap at about five frames per second, though it did not specify which Android versions that covers. Importantly, the Go program keeps running even after a victim deletes the malicious app, until the phone is restarted. Zimperium found that this program can also reinstall the app after removal and turn Accessibility access back on, making thorough cleanup difficult.
RatHat's developers use Gemini in two places. On the console side, Gemini scores each victim's likely bank balance, and an operator can set a Telegram alert to fire when a phone passes a chosen threshold. On the phone itself, the malware contains automated tap sequences designed for specific phone manufacturers, Android versions, and languages. When those hardcoded instructions fail on an unexpected device, the malware sends the screen layout to Gemini and asks it where to tap, calling the AI service directly from the phone with an API key stored in its own settings. Cleafy says this feature is only used to keep the wireless debugging setup working. This is not the first time Android malware has used this technique; ESET described a similar approach in February with a malware called PromptSpy that also sent Gemini the screen layout and followed its tap instructions.
Cleafy identified the console deployments by searching for their distinctive page titles and web code, counting console instances rather than infected phones. The company notes that their number of victims is not given in either report. Nearly half of the IP addresses Cleafy observed sit on one Singapore-registered network, AS4907. The consoles typically use web addresses beginning with "admin." and, for the latest version, "adminapi." on cheap top-level domains like .best, .beer, and .top. Once the Go program is active, the minicap and minitouch files sit in the /data/local/tmp directory on the phone under their real names, where a security scan can detect them. Cleafy advises that device monitoring tools should watch what runs as the shell user, identified by the Unix user ID (UID) 2000, to spot this and similar threats.
Monitoring network traffic for domains like those listed—something a privacy-focused DNS service such as AEU DNS can help with—gives site owners a layer of defense against stealthy phone malware that otherwise goes unnoticed. The indicators include command-and-control servers at admin.chunhuating[.]best, admin.xiongmaocs[.]pics, and 8.231.120[.]246, as well as download links at dramaspoolcoa[.]com and rathat[.]me, all of which can be blocked at the network level to interrupt the malware's communication.
How to Protect Yourself
- Only install apps from the official Google Play Store, not from links in text messages or third-party websites.
- Keep your phone's operating system updated, as newer Android versions block some of the malware's sneaky screen-recording tricks.
- Open your phone's accessibility settings and remove permissions for any app you don't recognize; this malware abuses that access to control the screen.
- If a pop-up asks you to allow wireless debugging and you didn't enable it yourself, deny it immediately and run a security scan using a trusted app.
- Restart your phone regularly—this temporarily stops the malware's hidden background program until the phone is exploited again.
- Use a security app that can monitor which programs run with elevated privileges on your device; the malware hides by running as the 'shell' user.
Terms Explained
- ADB Android Debug Bridge, a built-in Android tool that lets developers control a phone from a computer; the malware abuses it to take full control of the device.
- API key A secret code that lets a program identify itself to an online service; the malware stores a Google Gemini API key to ask the AI for help on infected phones.
- shell user A special system account on a device with elevated privileges; the malware runs as this user to bypass normal app restrictions.
- minicap/minitouch Tiny programs that can silently stream a phone screen and inject taps without showing a recording icon, used here to spy without alerting the victim.
- C2 Command and control, the server an attacker uses to send instructions to malware and receive stolen data.
- MD5 A digital fingerprint of a file, used to uniquely identify a specific malware sample.