RatHat shifts to malware-as-a-service with three C2 generations in six months
Cleafy found that RatHat's infrastructure evolves faster than the Android trojan itself: its command-and-control panels went through three generations in six months and rebranded from BlackCat to Panda Workshop. Nearly 100 deployments since April 2026 point to a malware-as-a-service model.
- C2 panels build, sign and publish Android samples directly from the operator console
- Panda Workshop V5 added 2FA for operators; V6 added a phishing download-page builder
- The panel uses Gemini to estimate victims' bank balances and rank devices by value
- Nearly half of observed campaign IP addresses sit on a single Singapore-based network
Read next
Security