CYBERSECURITYTRACKER
TRACKING
Permanent story citation

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8769

As cited

Copy frozen at (site build).

threat intel

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat is an Android banking trojan operated through a web console where individual customers run separate deployments. Cleafy identified nearly 100 instances of this console since April 2026, operating under a malware-as-a-service model, and documented the console's use of Google's Gemini to prioritize victims by financial value.

Why it matters: Financial institutions and users of Android banking apps face direct theft risk from RatHat's distributed operation; security teams should monitor for indicators of this malware family and related infrastructure.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary