Technology

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

The Hacker News September 28, 2026 1 views
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Advertisement

Security firm Cleafy has revealed that operators of the RatHat Android banking trojan are leveraging Google’s Gemini artificial intelligence model to identify and prioritize higher-value victims. The malware, which functions as a banking trojan, is controlled through a dedicated web console that allows attackers to manage infected devices and the data they collect.

According to Cleafy, the malware follows a malware-as-a-service (MaaS) model, where each customer operates a separate instance of the console. This structure enables multiple threat actors to deploy the tool independently while maintaining centralized control over their respective infected phones.

The security company has traced nearly 100 deployments of the RatHat console since April 2026. These deployments indicate a significant expansion in the use of the trojan, with operators actively building and publishing the malware to target Android users.

The web console serves as the primary interface for the attack, storing the sensitive information gathered from each compromised smartphone. By integrating Gemini, the operators aim to automate the analysis of this data to distinguish between low-value targets and those with greater financial significance.

This development highlights the increasing sophistication of cybercriminals, who are now embedding advanced AI capabilities into traditional banking trojans. The use of generative AI for victim triage represents a new layer of automation in the lifecycle of mobile malware attacks.

<small>Source: The Hacker News — read the original story there.</small>

How did this make you feel?

Never miss a story

Get the best of SpeakOX in your inbox. No spam, unsubscribe anytime.

Advertisement

Category
Technology

Advertisement