RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.

The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps.

Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups.

Nothing in the samples Cleafy analyzed uses the model to move money. Its role is "deciding which victims are worth an operator's time," the company said.

One Console, Three Versions

The malware on victims' phones has changed little since late 2025, Cleafy said. The console behind it has been replaced.

Samples from late 2025 and February 2026 connected to an earlier console named Fisher. Three new versions were in use between April and September 2026, all built from the same code.

The first calls itself BlackCat Remote Control Management. The next two are named Panda Workshop V5 and V6.

Every version is also a build tool. From the console, an operator can build the malware, hide it inside a harmless-looking app, and sign it. The console then publishes the finished app to Amazon S3 or to a web server, without the operator having to touch the hosting setup.

The console can also rebuild the app on a schedule, such as every hour. Each rebuild creates a new file from the same malware, which Cleafy said is aimed at security tools that spot known files by their hash.

The latest version also adds templates for fake download pages, including one called Google Store.

Shell Access in One Click

RatHat reaches phones through text messages and online ads that lead to third-party download sites, Zimperium found earlier this month.

Once installed, the app asks for Accessibility access, which lets an app read the screen and tap for the user. With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android.

That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app.

From the console, the operator can use that shell with one click, Cleafy found. A deploy button starts a separate program written in Go that stays reachable through a reverse tunnel, a connection the phone opens to the operator's server.

Pairing with ADB happens automatically, but the Go program runs only after the operator clicks deploy.

That program changes how the operator can watch the screen. Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs.

The Go program instead uses tools called minicap and minitouch to stream the screen and send taps, with no permission prompt and no recording icon.

Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt. Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers.

The Go program keeps running after the victim removes the app, until the phone restarts. Zimperium found that the program can also reinstall the app after it is deleted and turn its Accessibility access back on.

Neither report provides steps to remove the malware completely.

How Widely the Console Is Used

Cleafy found the deployments by searching for the console's page titles and web code. The figure counts console deployments, not infected phones.

Cleafy did not say what counts as one deployment, and neither its report nor Zimperium's gives several victims.

The console limits the number of operator accounts and hides some sections from non-admins. Cleafy said those limits only make sense if the users are customers the developers do not fully trust.

Nearly half of the IP addresses Cleafy observed are on one Singapore-registered network, AS4907.

Gemini on Both Ends

The first console version let operators pick from several AI providers, Cleafy found. It could also send a Telegram alert when a phone's AI score passed a set level.

The latest version works only with Gemini and directs operators to Google AI Studio to get a key.

RatHat also uses Gemini on the phone itself. Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate.

When that happens, the malware sends the screen's layout to Gemini and asks where to tap. It calls Gemini straight from the phone, using an API key stored in its own settings.

Cleafy said the feature is used only to keep the wireless debugging setup working.

Android malware has done this before. PromptSpy, which ESET described in February, also sent Gemini the screen layout and followed its tap instructions.

Indicators and Detection

Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples:

  • Domain: admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
  • Domain: admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
  • IP: 8.231.120[.]246 (C2 for BlackCat, April 2026)
  • Domain: admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
  • URL: hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
  • URL: hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
  • MD5: 116346cace7f00ba557034b534d40791 (sample, September 2026)
  • MD5: 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
  • MD5: f83357b2d47c7d38ee53943373961211 (sample, December 2025)

The consoles tend to use web addresses that start with admin., plus adminapi. for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top.

Once the Go program is deployed, the minicap and minitouch files sit in /data/local/tmp under their real names, where a scan can find them. Cleafy said security tools should watch what runs on phones as the shell user, UID 2000.

One of the listed addresses, admin.xiongmaocs[.]pics, also appears in the indicator list Zimperium released with its earlier analysis.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.