INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Gemini AI Used by RatHat Android Malware to Identify Victims

| 2026-09-28 18:56 LOW MEDIUM AI-ENABLED ATTACK MALWARE & BOTNETS
Executive Summary
AI-generated
Attackers distributed RATHat Android malware through malicious adverts and phishing text messages targeting Europe, Latin America on September 30, 2026. The attackers are believed to be behind the distribution of this banking trojan, which uses Gemini AI to control phones outside normal app permissions. Approximately 100 deployments of a web console have been traced since April 2026 by security company Cleafy, indicating a malware-as-a-service model. This console stores data from infected phones and uses Google's Gemini AI model to estimate each victim's bank balance, sorting them into high-value and mid-value groups. The current status is that the attackers continue to distribute RATHat Android malware through various channels, with no indication of immediate disruption or mitigation efforts being taken by authorities.
Technical Mitigations AI-generated
• Use a version of Android 10 or later to patch the exploit in the Accessibility service, which is used by RatHat to gain access to phone functionality. • Block or hunt for indicators of compromise such as <a href="/auth/login?next=/detail/Iuuy66ABAhlSTKR_aKR6" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> and <a href="/auth/login?next=/detail/Iuuy66ABAhlSTKR_aKR6" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>, which are associated with the distribution channels of the malware. • Detect the use of Gemini AI model in the console behind RatHat Android Malware by monitoring for signs of its presence, such as unusual network traffic or API calls to Google's servers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ww•••••.com
ad•••••.best
dr•••••.com
ad•••••.pics
en•••••.html
116346••••••••••••••••••••••••••
f83357••••••••••••••••••••••••••
8fdc21••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
8.231.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat
Target & Sectors
EUROPE EUROPE financefinance
Incident Timeline
‎late 2025
Threat actors used the Gemini AI by RatHat Android malware to control phones connected to an earlier console named Fisher, starting in late 2025.
organisation Fisher
‎December 2025
Threat actors used the admin.rathat[.]live domain as a C2 server to communicate with infected phones controlled by RatHat Android malware.
organisation hxxps://rathat[.]me
observable admin.rathat
observable app-release-rat-hat-live.apk
observable en.html
‎February 2026
Threat actors used the RatHat Android malware to control phones that downloaded and installed malicious apps from compromised websites linked to an earlier console named Fisher.
organisation hxxps://rathat[.]me
observable admin.rathat
observable app-release-rat-hat-live.apk
observable en.html
organisation Fisher
‎April 2026
Threat actors using the BlackCat Android malware have deployed a Gemini AI console nearly 100 times since April 2026.
general_metric 100 deployments
malware BlackCat
‎August 2026
Threat actors used the admin.xiongmaocs domain as a Command and Control (C2) server for Panda Workshop V5 malware, specifically targeting phones controlled by RatHat Android malware.
observable admin.xiongmaocs
‎September 2026
Threat actors used Gemini AI to control phones infected with RatHat Android malware, targeting devices through compromised download links and command-and-control servers.
observable admin.chunhuating
organisation Indicators and Detection Cleafy
organisation hxxps://rathat[.]me
observable admin.rathat
observable app-release-rat-hat-live.apk
observable en.html
‎between April and September 2026
RatHat Android malware utilized Gemini AI to control phones, with three new versions built from the same code between April and September 2026.
‎2026/09/28
Attackers used Gemini AI to control phones by distributing malicious adverts and phishing text messages targeting Europe, Latin America, and other regions.
infrastructure Android
organisation RatHat
organisation Identify Higher-Value Victims
organisation Control Phones Outside
organisation Gemini AI
organisation hxxps://rathat[.]me
organisation Google
organisation Cyber Security News
organisation IP
organisation Cleafy
organisation Amazon S3
organisation Shell Access
organisation Gemini
organisation Google AI Studio
organisation API
organisation PromptSpy
organisation ESET
organisation .best
organisation .beer
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product