RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization
RatHat Android RAT (TL-2026-2743) is a high-severity malware campaign, first published 2026-09-28 and last reviewed 2026-09-29. It is linked to a China-nexus actor with low confidence, affects Google Android, maps to 26 MITRE ATT&CK techniques (T1406, T1417.001, T1417.002), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-2743
- Threat ID
- TL-2026-2743
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-28
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- finance, banking
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 32
- Updates
- 2026-09-29 · revalidated 1× · latest source
Malware and tooling in RatHat Android RAT
Malware and tooling: PromptSpy, RatHat, RedHook, ScreenCap, ToxicPanda, VNCSpy, minicap, minitouch
RatHat is an Android banking RAT sold via a malware-as-a-service web console (evolved through Fisher, BlackCat Remote Control Management, and Panda Workshop V5/V6) with nearly 100 documented deployments since April 2026. It abuses Accessibility services to silently enable ADB wireless debugging and drive minicap/minitouch screen control, rebuilds APKs hourly to defeat hash-based detection, and its latest console queries Google's Gemini AI to estimate victims' bank balances from intercepted banking communications and triage high-value targets.
How RatHat Android RAT works
RatHat is distributed as a malware-as-a-service (MaaS) platform: operators rent access to a web console that builds Android banking-trojan APKs and manages infected devices. Cleafy Labs traced the console's lineage from Fisher (in operation December 2025-February 2026, C2 admin.rathat[.]live) through a rebuild branded BlackCat Remote Control Management in April 2026 (C2 IP 8.231.120[.]246), to Panda Workshop V5 in August 2026 (C2 admin.xiongmaocs[.]pics) and Panda Workshop V6 in September 2026 (C2 admin.chunhuating[.]best), documenting nearly 100 separate console deployments across that period consistent with a MaaS model where each customer runs an independent instance.
The malware's infection chain begins with Accessibility-service abuse: once a victim (via SMS smishing, malvertising, or a phishing/fake-app-store download page) grants Accessibility permissions, RatHat uses them to open Settings, enable Developer Options and Wireless Debugging without further prompts, read the six-digit ADB pairing code off the victim's own screen, and connect to the device's local ADB daemon over the loopback interface. This grants shell-level execution (UID 2000) without an attacker-controlled computer, bypassing normal Android runtime consent dialogs to silently grant permissions, disable background restrictions, and enforce persistence. This technique mirrors the wireless-ADB abuse recently documented in the ToxicPanda and RedHook Android RAT families.
The malware consists of three components: a Go-based agent (liblocal-service.so) that executes ADB shell commands, manages persistence, keylogs, and bypasses battery restrictions; an FRP-based reverse-proxy client (libmedia_codec.so) that opens a persistent tunnel back to operator infrastructure; and the main module handling credential theft, SMS interception, and UI automation via HTML overlays impersonating banking and cryptocurrency apps. For screen control, operators deploy a Go program that uses minicap and minitouch (on Android versions below 14) for undetected, permission-prompt-free screen streaming and synthetic taps, falling back to screencap at roughly five frames per second with a visible recording indicator on Android 14+ where minicap/minitouch no longer function without detection. Notably, the Go control program keeps running after the victim uninstalls the visible app, persisting until the device reboots; the two malicious components also mutually reinstall one another if either is removed, and the malware actively intercepts and blocks uninstall-confirmation dialogs.
To evade hash-based antivirus detection, the console can rebuild the distributed APK on a schedule (e.g., hourly), producing a new file hash from the same underlying malware each time. Anti-analysis measures include APK container tampering, an artificially bloated ~61MB AndroidManifest.xml, and invalid DEX pseudo-instructions intended to break static-analysis tooling.
The newest capability, introduced with Panda Workshop V6 in September 2026, has the console call Google's Gemini AI model against the SMS text and fake-overlay-captured credentials harvested from each infected phone to estimate that victim's bank balance, sorting devices into high-value and mid-value buckets so operators can prioritize manual follow-on fraud on the phones most worth their time -- Gemini is used for victim triage, not for automating the theft itself. Separately, RatHat also calls Gemini directly from the infected device at runtime, serializing the live Android Accessibility tree to XML and sending it to the model to determine where to tap when hard-coded UI automation fails across different device manufacturers, OEM skins, and Android versions -- solely to keep the wireless-debugging setup functioning across device diversity. Zimperium's concurrent, overlapping analysis (published September 16, 2026 by researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega) documents the same on-device technique in more general terms: RatHat serializes the Accessibility tree and asks an AI assistant for tap/scroll/read instructions rather than following a hardcoded script, and the researchers attribute the malware to China-nexus operators after finding LLM prompts written in simplified Chinese in the sample set. Zimperium also reports distribution via malvertising, SMS, and phishing sites hosting APKs outside Google Play.
This on-device LLM-driven UI automation technique was first documented in Android malware by ESET in February 2026 in a distinct but related family, PromptSpy (an evolution of VNCSpy, first seen on VirusTotal from Hong Kong on 2026-01-13), which used Gemini prompts plus an XML dump of on-screen UI elements to keep itself pinned in the recent-apps list for persistence, and which also carried simplified-Chinese debug strings and targeted Argentina via a dedicated distribution site (mgardownload[.]com) using a fake JPMorgan Chase ('MorganArg') dropper. Neither Cleafy nor Zimperium disclosed a specific victim count, named targeted banks, or a named threat-actor group for RatHat; the Chinese-language attribution is based on artifact language only.
MITRE ATT&CK techniques used in TL-2026-2743
Defense Evasion
T1406 Obfuscated Files or Information; T1629.001 Prevent Application Removal; T1633 Virtualization/Sandbox Evasion; T1655 Masquerading; T1655.001 Masquerading: Match Legitimate Name or Location
Credential Access
T1417.001 Keylogging; T1417.002 GUI Input Capture; T1453 Abuse Accessibility Features
Discovery
T1426 System Information Discovery
Collection
T1429 Audio Capture; T1512 Video Capture; T1513 Screen Capture; T1517 Access Notifications; T1636.003 Protected User Data: Contact List; T1636.004 SMS Messages
Command and Control
T1437.001 Web Protocols; T1544 Ingress Tool Transfer; T1572 Protocol Tunneling; T1663 Remote Access Software
defense-evasion
Persistence
T1541 Foreground Persistence; T1577 Compromise Application Executable
Resource Development
T1583.001 Acquire Infrastructure: Domains
Execution
Privilege Escalation
T1626 Abuse Elevation Control Mechanism
Initial Access
Affected products and versions in RatHat Android RAT
- Google — Android
Vulnerable versions: Android < 14 (minicap/minitouch enable undetected screen streaming and synthetic tap injection without permission prompts); Android 14+ (falls back to screencap at ~5 fps with a visible recording indicator; wireless-ADB shell abuse via Accessibility-service still functions)
Remediation for RatHat Android RAT
Immediate actions
- Block the documented RatHat C2 domains and IP (admin.chunhuating[.]best, admin.xiongmaocs[.]pics, admin.rathat[.]live, 8.231.120[.]246) and download URLs (dramaspoolcoa[.]com/en.html, rathat[.]me) at DNS/perimeter
- Enforce installation from Google Play only; block sideloading of APKs from SMS links, ad redirects, and third-party 'app store' pages
- Audit and restrict which apps hold Accessibility-service permissions on managed Android fleets; alert on newly granted Accessibility access followed by Developer Options / Wireless Debugging being enabled
- For infected devices, uninstall via Safe Mode (third-party apps disabled) and factory-reset if the malware resists removal, then perform a full device reboot to clear any surviving Go-agent processes
Workarounds
- Disable Wireless Debugging (Settings > Developer Options) when not actively used for legitimate development
- Keep Google Play Protect enabled; it provides automatic protection against known RatHat/PromptSpy variants
Longer-term hardening
- Deploy mobile threat defense (MTD) / EDR with behavioral detection for Accessibility-service abuse, wireless ADB pairing activity, and minicap/minitouch-style screen-streaming behavior
- Monitor for hourly-cadence APK hash churn against known malware-family behavioral signatures rather than relying on static hash blocklists
- Implement mobile banking app runtime protections (overlay/anti-screen-capture detection, root/ADB-debug detection) to detect when wireless debugging is active
- Track emerging on-device and console-side LLM API abuse (Gemini, other GenAI APIs) as a detection signal in mobile threat intel feeds
Timeline of RatHat Android RAT
- Fisher-branded RatHat console active (through February 2026), C2 admin.rathat[.]live, download URL rathat[.]me/app-release-rat-hat-live.apk; earliest sample hash f83357b2d47c7d38ee53943373961211 observed
- VNCSpy, the predecessor to the related on-device-LLM Android malware family PromptSpy, first appears on VirusTotal from Hong Kong
- February 2026 campaign uses a StripChat-themed decoy app with the Fisher panel (exact day not stated, first of month used).
- ESET discloses PromptSpy, the first documented Android malware to call Google Gemini at runtime (for recent-apps persistence), targeting Argentina; RatHat Fisher-era sample 8fdc21e25097a46528211274e54330e1 also dated to this period
- RatHat console rebuilt and rebranded 'BlackCat Remote Control Management'; Cleafy begins tracking console deployments from this point, eventually documenting nearly 100 instances; C2 IP 8.231.120[.]246 observed
- Panda Workshop V5 deployments begin (May-August 2026): TOTP 2FA for operators, an AI balance widget and an API namespace restructure (exact day not stated, first of month used).
- RedHook Android malware adds wireless-ADB abuse for computer-free shell access, part of the same technique trend RatHat uses
- Panda Workshop V5 console version deployed, C2 admin.xiongmaocs[.]pics; ToxicPanda 2.0 separately documented using the same wireless-ADB abuse technique with an expanded 167-command set
- Zimperium zLabs (Gianluca Braga, Vishnu Pratapagiri, Fernando Ortega) publishes overlapping RatHat analysis, documenting the three-component infection chain and attributing the malware to China-nexus operators based on simplified-Chinese LLM prompts found in samples
- Panda Workshop V6 console deployed with Gemini AI-driven victim bank-balance estimation and high/mid-value triage; C2 admin.chunhuating[.]best; sample hash 116346cace7f00ba557034b534d40791; download URL dramaspoolcoa[.]com/en.html
- Cleafy's research is publicly reported by The Hacker News, disclosing nearly 100 documented RatHat console deployments since April 2026 and the Gemini-driven victim-prioritization feature
- Infosecurity Magazine and other outlets report the Cleafy findings on the Gemini-assisted victim scoring.
Update history for TL-2026-2743
- 2026-09-29 — RatHat Android Banking Trojan MaaS: Evolving C2 Panel (BlackCat to Panda Workshop) with LLM-Driven Automated Transfers: What changed No severity/exploitability/status change (HIGH / ACTIVE already recorded). The record gains technical depth on the C2 panel and its capabilities. New indicators (11) Delivery domains dramaspoolcoa.com and rathat.me as standalon
Sources cited for RatHat Android RAT
- RatHat Android Malware Console Uses Gemini AI to Identify High-Value Victims
- New RatHat Android malware uses AI to automate device control
- New Android malware uses AI to steal bank logins and PINs
- RatHat Android Trojan Uses AI for Automation
- New 'RatHat' Android Malware Leverages AI to Steal Financial Data
- PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence
- PromptSpy ushers in the era of Android threats using GenAI
- ESET Research discovers PromptSpy, the first Android threat to use generative AI
- RedHook Android malware now uses Wireless ADB for shell access
- ToxicPanda Android malware uses VPN permissions to block Google Play
More in malware
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
Detection coverage for TL-2026-2743
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2743 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.