INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
RatHat's C2 Panel Evolves into Malware-as-a-Service Model
| 2026-09-28 20:24 MEDIUM MEDIUM MALWARE & BOTNETS
Executive Summary
AI-generated
The RatHat Android banking trojan has been observed to have undergone significant changes in its command-and-control (C2) panel, with three generations of panels emerging over six months. The infrastructure behind the malware has evolved into a Malware-as-a-Service model, where operators can build and publish new samples directly from their console. Nearly 100 separate deployments since April 2026 have been observed, consistent with this model. The C2 panels use AI to rank potential victims based on estimated bank balances, sorting devices into high-value and mid-value groups for operator identification. This technique has also allowed operators to identify targets without reviewing every infected phone by hand.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
dr•••••.com
ra•••••.me
ww•••••.com
ad•••••.live
8fdc21••••••••••••••••••••••••••
116346••••••••••••••••••••••••••
f83357••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat
Target & Sectors
EUROPE
EUROPE
LATAM
LATAM
APAC
APAC
financefinance
manufacturingmanufacturing
Incident Timeline
late 2025
Threat actors behind BlackCat shifted to Panda Workshop, a rebranded C2 panel, approximately six months after the initial implant deployment in late 2025.
Click on any entity below to view its context and source!
malware
BlackCat
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
organisation
Cleafy
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
April 2026
Nearly 100 separate deployments of malware since April 2026 are consistent with a malware-as-a-service model.
Click on any entity below to view its context and source!
general_metric
100 separate deployments
Nearly 100 separate deployments since April 2026 have been observed, consistent with a malware-as-a-service (MaaS) model.
September 2026
Threat actors using the BlackCat malware-as-a-service model updated its C2 panel to Panda Workshop, resulting in nearly 100 separate deployments across multiple regions.
Click on any entity below to view its context and source!
malware
BlackCat
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
organisation
Cleafy
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
between April and September 2026
Threat actors behind BlackCat deployed successive Command-and-Control panel generations, including Panda Workshop V5 and V6, between April and September 2026.
Click on any entity below to view its context and source!
malware
BlackCat
The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6.
organisation
Command
The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6.
September 28
Threat actors behind BlackCat rebranded their C2 panel as Panda Workshop, introducing a third generation of the control plane in approximately six months.
Click on any entity below to view its context and source!
malware
BlackCat
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
organisation
Cleafy
In
research
published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
2026/09/28
Threat actors used the Evolving C2 Panel behind RatHat to build, sign and publish new Android banking trojan samples directly from an operator console.
Click on any entity below to view its context and source!
infrastructure
Android
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point.
After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model.
The infrastructure behind the RatHat Android banking trojan has changed more than the malware itself, with successive command-and-control (C2) panels able to build malware, manage infected devices and use AI to rank potential victims.
RatHat C2 Becomes a Malware Factory
Cleafy said the panels could build, sign and publish new Android samples directly from the operator console.
Cleafy also found that operators could use RatHat's wireless debugging access to deploy a native Go service with a single click from the panel, gaining shell-level control outside the Android application's permission model.
The malware used Gemini separately: when its static automation failed on unfamiliar Android interfaces, the implant sent details of the screen to a large language model (LLM) and asked where to tap.
organisation
Accessibility Service
After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model.
organisation
IP
Campaigns ran in parallel across Europe, Latin America and Southeast Asia, and nearly half of the observed IP addresses sat on a single Singapore-based network.
organisation
RatHat
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model.
organisation
Evolving C2 Panel Points
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model.
organisation
Workshop V5
Panda Workshop V5 added two-factor authentication (2FA) for operators, and V6 added a phishing download-page builder.
organisation
Google
Cleafy said earlier panels supported multiple AI providers, but Panda Workshop V6 consolidated the configuration around Google's Gemini.
Tactical Metrics
Metrics
infrastructure
Android
Affected Product
Click for context!
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point.
After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model.
The infrastructure behind the RatHat Android banking trojan has changed more than the malware itself, with successive command-and-control (C2) panels able to build malware, manage infected devices and use AI to rank potential victims.
RatHat C2 Becomes a Malware Factory
Cleafy said the panels could build, sign and publish new Android samples directly from the operator console.
Cleafy also found that operators could use RatHat's wireless debugging access to deploy a native Go service with a single click from the panel, gaining shell-level control outside the Android application's permission model.
The malware used Gemini separately: when its static automation failed on unfamiliar Android interfaces, the implant sent details of the screen to a large language model (LLM) and asked where to tap.
Intelligence Sources
Infosecurity-Magazine
2026-09-29
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
Infosecurity-Magazine
AlienVault OTX
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T12:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
8x
organisation
Identified Entity
Accessibility Service
entity
5x
timeline
Temporal Reference
between April and September 2026
date
3x
target region
Target Region
EUROPE
region
Contextual Telemetry
Context Block
7 METRICS
industry
Targeted Sector
Finance
sector
infrastructure
Affected Product
Android
software
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
general metric
Separate Deployments
100
separate deployments
malware
Malware Payload
BlackCat
tool
target region
Target Country
Singapore
country
tactic
Cyber Operation Type
Phishing
tactic
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.