AI Weekly Malaysia

Back to items Summaries

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

ID
29443
Status
summarized
Published
29 Sep 2026, 1:38 AM
Fetched
29 Sep 2026, 2:53 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.0
Created
29 Sep 2026, 2:54 AM
Tags
Audience
developersai_ml_learnersfounders

What happened

Cleafy traced nearly 100 deployments since April 2026 of the RatHat Android banking-trojan console, run as malware-as-a-service where each customer operates a separate copy. The latest console versions — following an earlier one called Fisher and newer builds named BlackCat Remote Control Management and Panda Workshop V5/V6 — feed captured text messages and credentials from fake banking-app overlays to Google's Gemini to estimate each victim's bank balance and sort phones into high-value and mid-value groups; Cleafy found no use of the model to move money, only to decide 'which victims are worth an operator's time.' The console doubles as a build tool: it signs the malicious app, publishes it to Amazon S3 or a web server, and can rebuild it hourly to change the file hash, while the on-device malware abuses Accessibility access to enable wireless debugging, read the ADB pairing code off the screen, and open a shell through Android Debug Bridge.

Why it matters

Two concrete things to act on. First, the on-device chain is Accessibility access → enable wireless debugging → read the pairing code → ADB shell, so if you ship an Android app, that sequence — not generic 'mobile malware' — is what you should test against and consider detecting. Second, hourly rebuilds from the same malware source mean any pipeline relying on file-hash matching to spot known bad apps will miss these; if you use hash-based scanning for sideloaded builds, that gap is now demonstrated at ~100 console deployments. For anyone adding an LLM to a product, the Gemini use here is purely ranking/triage with no write access, which is the low-risk adoption pattern.

Discussion angle

The LLM here never moves money — it only ranks which victims an operator should spend time on. Is that the pattern most teams will actually ship first (model as prioritizer, human or code as actor), and if so, where is the line where you'd give a model write access? Pair that with the hourly-rebuild detail: what replaces hash-based detection for you?

Top