
RatHat Android Trojan Uses Gemini AI to Prioritize High-Value Banking Victims
Security researchers have identified RatHat, an Android banking trojan that leverages Google’s Gemini AI to navigate device interfaces and prioritize victims with high bank balances. The malware spreads via SMS phishing and malicious ads, requiring users to sideload apps and grant Accessibility permissions. Once installed, it exploits Wireless Debugging to gain shell-level access, intercepts two-factor authentication codes, and reconstructs PINs by analyzing touch coordinates. Cleafy reports that the malware’s control console uses AI to sort victims by financial value, while Zimperium notes its persistence mechanisms make removal difficult without a factory reset.













