RatHat Banking Trojan Uses Google's Gemini AI to Pick Its Richest Victims
Security firm Cleafy has identified nearly 100 deployments of a web-based control console used to run RatHat, an Android banking trojan sold under a malware-as-a-service model. The console stores text messages and fake login details stolen from infected phones, and its latest version sends this data to Google's Gemini AI model, which estimates each victim's bank balance and sorts them into high-value and mid-value groups. Cleafy found no evidence the AI is used to move stolen money, only to help operators decide which victims are worth pursuing.
While the malware itself has changed little since late 2025, the console behind it has been rebuilt several times, most recently as tools called Panda Workshop V5 and V6. These consoles let operators build, disguise, sign and automatically republish new versions of the malware on a schedule, making it harder for security tools that rely on recognising known files to keep up. The latest version also includes fake download page templates, including one mimicking the Google Play Store, to trick users into installing the app.
RatHat typically spreads through text messages and online ads linking to unofficial download sites. Once installed, it requests Accessibility access, which allows it to read the screen and simulate taps, enabling it to gain deeper, unauthorised control of the device.