RatHat Android malware console uses Gemini to pick higher-value victims
Security firm Cleafy has traced nearly 100 deployments of the RatHat console, which operators use to build and control an Android banking trojan from a web interface. The console taps Gemini to identify higher-value victims, following a malware-as-a-service model with a separate copy per customer.
- Cleafy traced nearly 100 RatHat console deployments since April 2026
- The console controls infected Android phones via a web interface
- Gemini is used to identify higher-value victims among infected devices
- Malware-as-a-service model: each customer runs a separate copy
Read next
Security