As cited
Copy frozen at (site build).
threat intel
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat is an Android banking trojan operated through a web console where individual customers run separate deployments. Cleafy identified nearly 100 instances of this console since April 2026, operating under a malware-as-a-service model, and documented the console's use of Google's Gemini to prioritize victims by financial value.
Why it matters: Financial institutions and users of Android banking apps face direct theft risk from RatHat's distributed operation; security teams should monitor for indicators of this malware family and related infrastructure.
- Source published
- First seen by Cybersecurity Tracker