INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Gemini AI Used by RatHat Android Malware to Identify Victims
| 2026-09-28 18:56 LOW MEDIUM AI-ENABLED ATTACK MALWARE & BOTNETS
Executive Summary
AI-generated
Attackers distributed RATHat Android malware through malicious adverts and phishing text messages targeting Europe, Latin America on September 30, 2026. The attackers are believed to be behind the distribution of this banking trojan, which uses Gemini AI to control phones outside normal app permissions. Approximately 100 deployments of a web console have been traced since April 2026 by security company Cleafy, indicating a malware-as-a-service model. This console stores data from infected phones and uses Google's Gemini AI model to estimate each victim's bank balance, sorting them into high-value and mid-value groups. The current status is that the attackers continue to distribute RATHat Android malware through various channels, with no indication of immediate disruption or mitigation efforts being taken by authorities.
Technical Mitigations AI-generated
• Use a version of Android 10 or later to patch the exploit in the Accessibility service, which is used by RatHat to gain access to phone functionality.
• Block or hunt for indicators of compromise such as <a href="/auth/login?next=/detail/Iuuy66ABAhlSTKR_aKR6" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> and <a href="/auth/login?next=/detail/Iuuy66ABAhlSTKR_aKR6" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>, which are associated with the distribution channels of the malware.
• Detect the use of Gemini AI model in the console behind RatHat Android Malware by monitoring for signs of its presence, such as unusual network traffic or API calls to Google's servers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ww•••••.com
ad•••••.best
dr•••••.com
ad•••••.pics
en•••••.html
116346••••••••••••••••••••••••••
f83357••••••••••••••••••••••••••
8fdc21••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
8.231.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat
Target & Sectors
EUROPE
EUROPE
financefinance
Incident Timeline
late 2025
Threat actors used the Gemini AI by RatHat Android malware to control phones connected to an earlier console named Fisher, starting in late 2025.
Click on any entity below to view its context and source!
organisation
Fisher
Samples from late 2025 and February 2026 connected to an earlier console named Fisher.
December 2025
Threat actors used the admin.rathat[.]live domain as a C2 server to communicate with infected phones controlled by RatHat Android malware.
Click on any entity below to view its context and source!
organisation
hxxps://rathat[.]me
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
admin.rathat
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
app-release-rat-hat-live.apk
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
en.html
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
February 2026
Threat actors used the RatHat Android malware to control phones that downloaded and installed malicious apps from compromised websites linked to an earlier console named Fisher.
Click on any entity below to view its context and source!
organisation
hxxps://rathat[.]me
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
admin.rathat
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
app-release-rat-hat-live.apk
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
en.html
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
organisation
Fisher
Samples from late 2025 and February 2026 connected to an earlier console named Fisher.
April 2026
Threat actors using the BlackCat Android malware have deployed a Gemini AI console nearly 100 times since April 2026.
Click on any entity below to view its context and source!
general_metric
100 deployments
Cleafy has traced nearly 100 deployments of that console since April 2026.
Cleafy has
traced nearly 100 deployments
of that console since April 2026.
malware
BlackCat
IP
: 8.231.120[.]246 (C2 for BlackCat, April 2026)
August 2026
Threat actors used the admin.xiongmaocs domain as a Command and Control (C2) server for Panda Workshop V5 malware, specifically targeting phones controlled by RatHat Android malware.
Click on any entity below to view its context and source!
observable
admin.xiongmaocs
Domain
: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
September 2026
Threat actors used Gemini AI to control phones infected with RatHat Android malware, targeting devices through compromised download links and command-and-control servers.
Click on any entity below to view its context and source!
observable
admin.chunhuating
Indicators and Detection
Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples:
Domain
: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
organisation
Indicators and Detection
Cleafy
Indicators and Detection
Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples:
Domain
: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
organisation
hxxps://rathat[.]me
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
admin.rathat
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
app-release-rat-hat-live.apk
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
observable
en.html
Domain
: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL
: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL
: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5
: 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5
: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5
:…
between April and September 2026
RatHat Android malware utilized Gemini AI to control phones, with three new versions built from the same code between April and September 2026.
2026/09/28
Attackers used Gemini AI to control phones by distributing malicious adverts and phishing text messages targeting Europe, Latin America, and other regions.
Click on any entity below to view its context and source!
infrastructure
Android
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims.
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy.
Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin […] The post RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions.
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions.
With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android.
That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app.
Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs.
Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt.
Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers.
Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate.
Android malware has done this before.
organisation
RatHat
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims.
organisation
Identify Higher-Value Victims
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims.
organisation
Control Phones Outside
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions.
organisation
Gemini AI
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions.
Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups.
organisation
hxxps://rathat[.]me
hxxps://www[.]cleafy[.]com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
Indicators of compromise:
admin[.]chunhuating[.]best
admin[.]xiongmaocs[.]pics
8[.]231[.]120[.]246
admin[.]rathat[.]live
hxxps://dramaspoolcoa[.]com/en[.]html
hxxps://rathat[.]me/app-release-rat-hat-live[.]apk
116346cace7f00ba557034b534d40791
8fdc21e25097a46528211274e54330e1
f83357b…
organisation
Google
Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups.
organisation
Cyber Security News
Permissions appeared first on Cyber Security News .
organisation
IP
Nearly half of the IP addresses Cleafy observed are on one Singapore-registered network, AS4907.
Gemini on Both Ends
The first console version let operators pick from several AI providers, Cleafy found.
organisation
Cleafy
Nothing in the samples Cleafy analyzed uses the model to move money.
organisation
Amazon S3
The console then publishes the finished app to Amazon S3 or to a web server, without the operator having to touch the hosting setup.
organisation
Shell Access
Shell Access in One Click
RatHat reaches phones through text messages and online ads that lead to third-party download sites,
Zimperium found earlier this month
.
organisation
Gemini
The latest version works only with Gemini and directs operators to Google AI Studio to get a key.
organisation
Google AI Studio
The latest version works only with Gemini and directs operators to Google AI Studio to get a key.
organisation
API
It calls Gemini straight from the phone, using an API key stored in its own settings.
organisation
PromptSpy
PromptSpy
, which ESET described in February, also sent Gemini the screen layout and followed its tap instructions.
organisation
ESET
PromptSpy
, which ESET described in February, also sent Gemini the screen layout and followed its tap instructions.
organisation
.best
for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top.
organisation
.beer
for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top.
Tactical Metrics
Metrics
infrastructure
Android
Affected Product
Click for context!
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims.
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy.
Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin […] The post RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions.
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions.
With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android.
That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app.
Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs.
Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt.
Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers.
Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate.
Android malware has done this before.
Intelligence Sources
The Hacker News
2026-09-28
AlienVault OTX
2026-09-28
AlienVault OTX
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
RatHat
entity
7x
timeline
Temporal Reference
April 2026
date
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Android
software
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
general metric
Deployments
100
deployments
tactic
Cyber Operation Type
Phishing
tactic
target region
Target Region
EUROPE
region
target region
Target Country
Singapore
country
general metric
Uid
2,000
uid
general metric
Android
14
android
general metric
Frames
5
frames
malware
Malware Payload
BlackCat
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.