Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

RatHat Android banking trojan's console uses Gemini to rank victims, Cleafy says

Security firm Cleafy says the malware's control panel asks Gemini to estimate each victim's balance from stolen texts, then sorts phones into high- and mid-value groups.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Cleafy says the RatHat Android banking trojan's console uses Gemini to estimate victims' bank balances from stolen text messages.
  • 2Cleafy traced nearly 100 console deployments since April 2026, a count of panels, not infected phones.
  • 3The malware can give itself shell access through wireless debugging and asks Gemini where to tap on screen.

The news

Security firm Cleafy said on September 28 that the RatHat Android banking trojan's control console uses Google's Gemini AI models to estimate victims' bank balances and sort infected phones into high-value and mid-value groups, helping operators choose whom to target first.

The console stores what the malware takes from each phone, including text messages and the credentials victims type into fake login pages shown on top of banking apps, as reported by The Hacker News. According to Cleafy's report, which spells the name RATHat, the panel uses a large language model to pull bank balances out of the collected SMS messages and score each device. The latest version, which Cleafy calls Panda Workshop V6 and dates to August and September 2026, is configured only for Gemini models from Google, part of Alphabet (GOOGL), and can send operators Telegram alerts when a score passes a threshold they set.

Cleafy said the AI also works on the phone itself. When the malware cannot find its way around an unfamiliar phone interface or language, it sends the screen's layout to Gemini and asks where to tap, according to both Cleafy and The Hacker News. The Hacker News reported that the malware queries Gemini from the device itself, using an API key kept in the malware's configuration.

The Hacker News described RatHat as malware-as-a-service, a model in which developers supply ready-made tooling to criminal customers. Cleafy said each customer runs its own instance of the console. It traced nearly 100 unique deployments since April 2026. The Hacker News noted that the figure counts consoles, not infected phones. Cleafy said nearly half of the observed IPv4 addresses sat on AS4907, a network registered in Singapore.

Cleafy analysed three generations of the panel, all built from the same code: BlackCat, which appeared in April 2026, followed by Panda Workshop V5, used from May to August 2026, and V6. It left out an earlier console called Fisher, tied to campaigns in December 2025, because it shares no code with the later versions. The malware reaches phones through malicious ads and smishing, or SMS phishing, that lead to third-party download sites, according to Cleafy and earlier research by Zimperium cited by The Hacker News. Cleafy said targeting spans Europe, Latin America and Southeast Asia.

Beyond overlays and SMS theft, Cleafy said RatHat switches on wireless debugging by itself and pairs with the Android Debug Bridge (ADB), a developer tool, to obtain a shell running as user ID 2000. That lets it capture the screen without a consent prompt on older phones; Cleafy said the tools behind this do not work on Android 14 and later, which leaves the malware with a capture method that asks the user for consent. Cleafy's report lists more than 100 commands and says a background service survives removal of the app until the phone reboots.

The numbers

RatHat console deployments traced since April 2026
Nearly 100 (Cleafy; counts panels, not infected phones)
Share of observed IPv4 addresses on AS4907 (Singapore)
Nearly half (Cleafy)
Commands supported by the malware
More than 100 (listed in Cleafy's report)
Console generations analysed
3, April to September 2026 (Cleafy; excludes the earlier Fisher panel)

Why CEOs should care

For banks and payment firms, the change is in who gets targeted. If operators rank infected phones by estimated balance, customers with larger accounts are more likely to see a hands-on fraud attempt. Fraud leaders should ask whether their controls can spot account takeover performed on the customer's own device, since RatHat can see the screen, read texts and tap through apps. Cleafy recommends watching for processes running as user ID 2000 and preparing for fraud automation guided by AI models.

Because RatHat reads SMS messages, one-time passcodes sent by text offer weak protection on an infected phone. Product and risk teams should review which high-value actions still rely on SMS codes and whether app-bound or device-bound approvals are available. Customer-facing teams can also warn users about apps from third-party sites promoted through ads or text messages.

CISOs with bring-your-own-device policies face the same threat on staff phones. Mobile device management settings that block installs from unknown sources and flag developer options or wireless debugging reduce exposure. Phones on older Android versions carry more risk, since Cleafy said the malware's prompt-free screen capture does not work on Android 14 and later. Boards should note that criminals are building the same commercial AI services their own companies use into fraud tooling.

The bigger picture

RatHat is not the first Android malware to lean on Gemini. The Hacker News noted that PromptSpy, which ESET described in February, likewise relied on Gemini to read the on-screen interface and tell it where to tap. What stands out in Cleafy's findings is the triage role: the model helps decide where operators spend their effort, turning stolen text messages into a ranked target list. Cleafy also warned that other malware families might copy RatHat's approach of giving itself shell access instead of asking the user for permissions.

What’s next

Zimperium has published indicators of compromise for RatHat, and Cleafy said the panel is still evolving, with its newest version adding a phishing page builder. Banks operating in Europe, Latin America and Southeast Asia should check those indicators against their fraud telemetry and watch for new console versions.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

RatHatCleafyGoogle GeminiAndroid malwareBanking fraud

Earlier coverage of Google

All Google coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.