RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims

Security researchers have identified RatHat, an Android banking trojan that leverages Google’s Gemini AI to navigate device interfaces and prioritize victims with high bank balances. The malware spreads via SMS phishing and malicious ads, requiring users to sideload apps and grant Accessibility permissions. Once installed, it exploits Wireless Debugging to gain shell-level access, intercepts two-factor authentication codes, and reconstructs PINs by analyzing touch coordinates. Cleafy reports that the malware’s control console uses AI to sort victims by financial value, while Zimperium notes its persistence mechanisms make removal difficult without a factory reset.
Key points
- RatHat spreads through SMS phishing, malicious advertising, and fake download sites posing as legitimate apps like Chrome or streaming services.
- The malware requires users to manually install APKs outside Google Play and grant Accessibility permissions to function.
- It abuses Wireless Debugging to connect to the Android Debug Bridge (ADB), gaining shell-level access outside the standard app sandbox.
- Gemini AI is used on the device to navigate interfaces and on the operator’s console to estimate bank balances and prioritize high-value targets.
- The malware intercepts SMS messages for 2FA codes and reconstructs PINs by analyzing raw touch coordinates against keypad layouts.
- Persistence is maintained via a Go-based agent and reverse-proxy tunnel that survive app uninstallation, often requiring a factory reset for removal.
Background
RatHat has been under scrutiny since late 2025, with earlier reports linking it to Chinese actors and highlighting its use of AI for UI automation. Recent coverage in September 2026 confirmed its expansion into Europe and Canada, often alongside similar malware like RemControl. The current reports detail the evolution of its command-and-control infrastructure and the specific integration of Gemini for victim prioritization.
How outlets are covering it
Zimperium emphasizes the technical mechanics of RatHat, focusing on how it abuses Accessibility and Wireless Debugging to gain deep control and the difficulty of removal due to persistent background services. Cleafy provides a broader operational view, identifying the malware-as-a-service model, tracing nearly 100 console deployments since April 2026, and highlighting the use of Gemini to sort victims by financial value. Fox News focuses on consumer protection advice, stressing the importance of avoiding sideloaded apps and keeping Play Protect enabled. While all sources agree on the AI-driven nature of the threat, Cleafy notes that the AI is used for triage rather than direct money movement, whereas Zimperium highlights the AI’s role in real-time navigation and evasion.
Why it matters
RatHat represents a significant escalation in Android malware sophistication by combining social engineering with AI-driven interface navigation and victim prioritization. Its ability to bypass standard security measures like screen readers and PIN hiding techniques, along with its persistent nature, poses a severe risk to financial security. The reliance on user action (sideloading and permission grants) highlights the continued importance of user vigilance and the limitations of automated protections like Play Protect against novel threats.
What to watch
Security firms are likely to update detection signatures for the new console versions (Panda Workshop V5/V6, BlackCat) and the specific ADB shell behaviors. Users are advised to monitor for unexpected Accessibility requests and Wireless Debugging activations. Google may issue further updates to Play Protect to detect the specific indicators of compromise listed by Cleafy, such as the minicap and minitouch tools in /data/local/tmp.
- Android malware can steal your PIN and bank logins Fox News
- RATHat Android Banking Trojan Uses Gemini AI and ADB Shell to Take Control of Devices cyberpress.org
- RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims The Hacker News
- Group-IB uncovers RemControl, the Android banking trojan built with AI help Pasquale Pillitteri
- RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model Infosecurity Magazine
Want the full story? Read the original reporting
Read on Fox News