Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-1 of 1 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 29 Sep 2026, 1:38 AM | The Hacker News | 6.0 | RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Cleafy traced nearly 100 deployments since April 2026 of the RatHat Android banking-trojan console, run as malware-as-a-service where each customer operates a separate copy. The latest console versions — following an earlier one called Fisher and newer builds named BlackCat Remote Control Management and Panda Workshop V5/V6 — feed captured text messages and credentials from fake banking-app overlays to Google's Gemini to estimate each victim's bank balance and sort phones into high-value and mid-value groups; Cleafy found no use of the model to move money, only to decide 'which victims are worth an operator's time.' The console doubles as a build tool: it signs the malicious app, publishes it to Amazon S3 or a web server, and can rebuild it hourly to change the file hash, while the on-device malware abuses Accessibility access to enable wireless debugging, read the ADB pairing code off the screen, and open a shell through Android Debug Bridge. Why: Two concrete things to act on. First, the on-device chain is Accessibility access → enable wireless debugging → read the pairing code → ADB shell, so if you ship an Android app, that sequence — not generic 'mobile malware' — is what you should test against and consider detecting. Second, hourly rebuilds from the same malware source mean any pipeline relying on file-hash matching to spot known bad apps will miss these; if you use hash-based scanning for sideloaded builds, that gap is now demonstrated at ~100 console deployments. For anyone adding an LLM to a product, the Gemini use here is purely ranking/triage with no write access, which is the low-risk adoption pattern. |