The latest analysis of RatHat shows that the malware is evolving beyond a conventional Android banking trojan into a much more complete Malware-as-a-Service ecosystem. Cleafy says the command-and-control infrastructure behind RatHat has undergone three major generations in roughly six months, moving from a platform known as BlackCat to what is now branded as Panda Workshop. The console does far more than display infected devices. It can build, sign, publish, and periodically regenerate Android malware samples, manage victims, control infected phones, and now use Google Gemini to help operators identify which compromised devices may be the most valuable.

That AI integration is important because it changes the operator workflow. Traditional banking malware panels may show hundreds or thousands of infected devices and leave a human criminal to manually inspect each one. RatHat’s console can instead feed victim information into Gemini and ask the model to rank or summarize devices based on factors that may indicate higher financial or operational value. In effect, AI becomes a triage assistant for the criminal operator. The malware still steals credentials and controls devices using familiar techniques, but the C2 platform helps determine where the attacker should spend human attention first.

This is a meaningful evolution because cybercrime at scale often runs into a very mundane limitation: operator time. Infecting thousands of devices is relatively easy compared with manually examining thousands of victims, identifying which ones have useful banking apps or cryptocurrency wallets, and deciding which sessions are worth actively manipulating. AI can reduce that bottleneck by summarizing telemetry and prioritizing the most promising targets.

Cleafy says it has traced nearly 100 separate RatHat console deployments since April 2026, which is consistent with a Malware-as-a-Service model where individual affiliates or customers operate their own panel instances. This means RatHat should not be viewed as one actor controlling one campaign. The infrastructure appears designed to be replicated and sold or licensed to multiple operators, potentially targeting different regions simultaneously. Cleafy observed activity across Europe, Latin America, and Southeast Asia.

The RatHat ecosystem is especially interesting because the Android malware itself has remained relatively stable while the control infrastructure around it has evolved rapidly. This suggests the operators are investing heavily in operational efficiency, not merely adding more malware features. A mature criminal platform needs deployment automation, victim management, licensing, payload generation, telemetry, remote control, and now AI-assisted victim prioritization. RatHat is increasingly showing all of those characteristics.

The panel reportedly acts as a complete malware factory. Operators can generate new APKs, sign them, host them, and rebuild them on a schedule without directly interacting with the underlying infrastructure. Periodic recompilation can change hashes and reduce the usefulness of simple signature-based detection. This lowers the technical barrier for affiliates because the user of the platform does not need to understand Android development, certificate signing, hosting, or malware packaging in depth. The panel abstracts those tasks behind a web interface.

That is one of the more significant trends in cybercrime generally. Malware-as-a-Service increasingly resembles legitimate SaaS. The criminal customer is presented with an interface that hides the complexity underneath. The provider handles infrastructure, builds, persistence mechanisms, and updates. The affiliate simply selects victims and launches operations. AI assistance fits naturally into that model because it can reduce the expertise required even further.

RatHat was already unusual because its malware uses AI directly on compromised devices. Zimperium’s earlier analysis found that the trojan serializes the Android Accessibility tree into XML and sends it to a generative AI service. The AI returns information about where to tap, which text appears on screen, or whether the malware should scroll. Instead of relying entirely on hardcoded coordinates or scripts for every Android version and device layout, RatHat can adapt to what is actually visible on the screen.

This is a significant technical advantage. Android interfaces vary by manufacturer, operating-system release, language, screen resolution, installed applications, and accessibility configuration. Traditional malware often needs large libraries of rules to handle those variations. An AI model capable of interpreting the live accessibility tree can provide a more flexible navigation layer.

That AI-driven UI capability supports one of RatHat’s most important privilege-escalation techniques. After the victim grants Accessibility permissions, the malware can navigate Android settings, enable Developer Options and Wireless Debugging, read the six-digit ADB pairing code displayed on the device, and pair with the phone’s own Android Debug Bridge interface. It essentially uses the victim’s phone to pair with itself.

Once the self-pairing succeeds, RatHat gains a shell-level ADB context without requiring an external computer. That represents a substantial increase in capability beyond what a normal Android application receives through the standard sandbox. The malware then deploys native Go components that can execute commands and maintain a reverse tunnel back to attacker infrastructure.

This architecture also helps the malware survive removal. The malicious Android application can be uninstalled while the native component operating through the ADB context remains active until reboot. That background component can then reinstall or restore the malicious application and its permissions. For victims and even some mobile-security tooling, removing the visible app may therefore create a false sense of remediation.

RatHat also contains the familiar capabilities expected from modern Android banking malware. It can display phishing overlays on top of legitimate banking, payment, or cryptocurrency applications to capture usernames, passwords, PINs, and other credentials. It can intercept SMS messages and one-time passwords, monitor notifications, and collect device information.

One of the more technically interesting features involves the theft of lock-screen secrets. Researchers found that RatHat can capture raw touch coordinates from the device’s input system and compare those coordinates against known keypad or pattern-lock layouts. This allows it to reconstruct PIN codes or Android unlock patterns without relying solely on ordinary screen-reading mechanisms.

That capability is particularly important because mobile operating systems increasingly attempt to prevent sensitive values such as PINs from being exposed through accessibility APIs or screenshots. Monitoring raw input coordinates provides the attacker with an alternate channel.

The combination of those capabilities makes RatHat substantially more dangerous than a simple overlay trojan. The malware can potentially move from application-level credential theft into a form of persistent remote device control, with shell-level access, reverse tunneling, credential interception, and AI-assisted navigation.

The new C2 research adds another layer: AI is now being used on both sides of the compromise. On the victim device, it can assist navigation. In the operator console, it can assist victim selection.

That distinction is worth emphasizing because descriptions such as “AI-powered malware” can easily become meaningless. RatHat provides a much more concrete example of how AI can be integrated into criminal operations at different stages.

The first role is tactical automation: interpret the mobile interface and determine where to interact.

The second is operational prioritization: analyze victim telemetry and identify which devices may offer the greatest financial value.

Neither capability requires an AI system to autonomously run the entire criminal operation. The human remains in control. What AI does is reduce the amount of repetitive work the operator needs to perform.

This may ultimately be more significant than fully autonomous malware. Cybercriminal organizations do not necessarily need AI to replace the attacker. They need AI to let one attacker manage more victims.

If a single operator previously had time to inspect 20 compromised devices in an evening, an AI-assisted console that summarizes and ranks hundreds of devices can dramatically increase the economic efficiency of the operation.

That has direct implications for fraud teams. In banking malware campaigns, the number of infections is not necessarily the same as the number of monetized victims. Criminals frequently select high-value accounts for manual intervention, especially where fraudulent transfers require interactive device control or real-time manipulation of banking sessions.

An AI system that can surface devices containing specific banking apps, cryptocurrency wallets, account balances, regional indicators, or other high-value characteristics makes that selection process much faster.

The same principle could expand beyond banking malware. An AI-assisted criminal console could prioritize corporate executives, administrators, developers, cryptocurrency holders, high-net-worth individuals, or devices associated with particular organizations.

That creates a shift from mass infection followed by manual triage toward mass infection followed by automated intelligence analysis.

The panel’s evolution also reinforces the importance of treating malware infrastructure as a product. Cleafy observed three generations of the console in six months, suggesting active development and customer feedback. Features are being improved not simply to evade antivirus but to make affiliates more productive.

That is how successful Malware-as-a-Service ecosystems mature. They compete on usability, reliability, support, evasion, automation, and profitability just as legitimate software platforms compete on features.

The emergence of AI inside these consoles is therefore not surprising. If AI can help legitimate businesses prioritize sales leads, summarize customers, or automate support workflows, criminals can apply exactly the same technology to compromised devices.

From the defensive side, RatHat’s initial infection still depends heavily on social engineering. Victims are typically directed through malicious advertising, SMS phishing, third-party forums, or fake download sites and persuaded to sideload an APK outside Google Play. The malware then needs Accessibility permissions to begin its more advanced automation.

That provides defenders with important intervention points. Preventing sideloading on managed Android devices remains one of the strongest controls. Enterprise mobility-management platforms should restrict installation from unknown sources and monitor for applications requesting high-risk Accessibility privileges.

Accessibility access should be treated as highly sensitive. An application that does not have a legitimate accessibility purpose should not normally receive permission to inspect screen content and perform clicks on behalf of the user.

Wireless Debugging is another important signal. It is a legitimate development feature, but it is rarely required on ordinary corporate or consumer phones. Enabling Developer Options and Wireless Debugging unexpectedly, particularly shortly after installing an untrusted APK, should be treated as suspicious.

Organizations with managed Android fleets should consider policies that disable or monitor debugging functionality and alert on unusual ADB-related activity.

The persistence mechanism also means incident response needs to go beyond deleting the malicious application. If RatHat has already established an ADB shell and installed its native components, the device may remain compromised after the APK disappears. A reboot, detailed forensic assessment, or complete device reset may be required depending on what stage of the infection was reached.

Credentials and sessions exposed on the phone should also be treated as potentially compromised. That includes banking credentials, enterprise passwords, cryptocurrency accounts, email sessions, SMS-based MFA codes, and any secrets accessible through applications targeted by overlays.

For financial institutions, behavioral fraud detection becomes particularly important because malware such as RatHat increasingly operates directly from the victim’s trusted device. Transactions may originate from the correct phone, correct SIM, familiar IP range, and an authenticated banking session.

Traditional device-reputation checks may therefore be insufficient.

Banks need contextual signals such as unusual transfer beneficiaries, changes in interaction patterns, suspicious accessibility usage, remote-control indicators, unexpected transaction velocity, and inconsistencies between the user’s normal behavior and the actions being performed.

RatHat also reinforces a larger trend: mobile malware is becoming an automation platform rather than merely a credential-stealing application.

The attack chain increasingly looks like:

smishing or malvertising → sideloaded APK → Accessibility abuse → AI-assisted navigation → Developer Options and Wireless Debugging → self-paired ADB shell → native Go agent and reverse tunnel → overlays and credential theft → persistent remote control → AI-assisted victim prioritization in the C2 panel

That is a substantial evolution from the older banking-trojan model.

The broader cybersecurity lesson is not that AI suddenly created mobile malware. Almost every underlying technique already existed: overlays, Accessibility abuse, ADB manipulation, SMS interception, reverse proxies, credential theft, and Malware-as-a-Service.

What AI changes is adaptability and scale.

On the endpoint, it can reduce dependence on rigid scripts.

On the backend, it can reduce the operator’s need to manually inspect every victim.

That combination matters because cybercrime has always been constrained by human time. AI removes some of that constraint.

The RatHat ecosystem therefore provides a useful glimpse of where financially motivated malware operations may be heading: human-directed, AI-assisted criminal platforms where automation handles the repetitive work and operators concentrate on the victims most likely to produce money.

The danger is not necessarily a fully autonomous AI hacker.

It may simply be one human attacker who can now manage ten times as many compromised devices.


RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

Source: RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims via The Hacker News — published 28 Sep 2026.