Malware · 6h ago
Cleafy traced nearly 100 RatHat console deployments since April 2026, and the latest Android banking-trojan console now uses Google Gemini to sort victims by estimated bank balance. RatHat’s operators already used the console to collect text messages and credentials from fake login overlays; now the same data is fed into Gemini to separate higher-value phones from the rest.
In plain terms, the console asks an AI model to guess who likely has money, then ranks those victims first. Cleafy said the model is not being used to move funds; it is being used to decide which accounts are worth an operator’s time, which makes the theft pipeline more selective and more efficient.
For teams that watch Android fraud, the lasting change is triage: a partial compromise can be enough to surface the accounts most worth pursuing. Anywhere stolen messages and app-overlay credentials are already being collected, the exposure now includes automated targeting, not just data theft.
2 sources covering this story
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
RatHat's C2 panel now builds malware and ranks victims with AI across nearly 100 deployments
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Cleafy traced nearly 100 RatHat console deployments since April 2026, with the platform building malware and using Gemini to rank victims.
Part of the PlainSec briefing for 2026-09-29