RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization

RatHat Android RAT (TL-2026-2743) is a high-severity malware campaign, first published 2026-09-28 and last reviewed 2026-09-29. It is linked to a China-nexus actor with low confidence, affects Google Android, maps to 26 MITRE ATT&CK techniques (T1406, T1417.001, T1417.002), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-2743

Threat ID
TL-2026-2743
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-28
Last reviewed
2026-09-29
Attribution confidence
LOW
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
Global
Detection rules
9
Indicators of compromise
32
Updates
2026-09-29 · revalidated 1× · latest source

Malware and tooling in RatHat Android RAT

Malware and tooling: PromptSpy, RatHat, RedHook, ScreenCap, ToxicPanda, VNCSpy, minicap, minitouch

RatHat is an Android banking RAT sold via a malware-as-a-service web console (evolved through Fisher, BlackCat Remote Control Management, and Panda Workshop V5/V6) with nearly 100 documented deployments since April 2026. It abuses Accessibility services to silently enable ADB wireless debugging and drive minicap/minitouch screen control, rebuilds APKs hourly to defeat hash-based detection, and its latest console queries Google's Gemini AI to estimate victims' bank balances from intercepted banking communications and triage high-value targets.

How RatHat Android RAT works

RatHat is distributed as a malware-as-a-service (MaaS) platform: operators rent access to a web console that builds Android banking-trojan APKs and manages infected devices. Cleafy Labs traced the console's lineage from Fisher (in operation December 2025-February 2026, C2 admin.rathat[.]live) through a rebuild branded BlackCat Remote Control Management in April 2026 (C2 IP 8.231.120[.]246), to Panda Workshop V5 in August 2026 (C2 admin.xiongmaocs[.]pics) and Panda Workshop V6 in September 2026 (C2 admin.chunhuating[.]best), documenting nearly 100 separate console deployments across that period consistent with a MaaS model where each customer runs an independent instance.

The malware's infection chain begins with Accessibility-service abuse: once a victim (via SMS smishing, malvertising, or a phishing/fake-app-store download page) grants Accessibility permissions, RatHat uses them to open Settings, enable Developer Options and Wireless Debugging without further prompts, read the six-digit ADB pairing code off the victim's own screen, and connect to the device's local ADB daemon over the loopback interface. This grants shell-level execution (UID 2000) without an attacker-controlled computer, bypassing normal Android runtime consent dialogs to silently grant permissions, disable background restrictions, and enforce persistence. This technique mirrors the wireless-ADB abuse recently documented in the ToxicPanda and RedHook Android RAT families.

The malware consists of three components: a Go-based agent (liblocal-service.so) that executes ADB shell commands, manages persistence, keylogs, and bypasses battery restrictions; an FRP-based reverse-proxy client (libmedia_codec.so) that opens a persistent tunnel back to operator infrastructure; and the main module handling credential theft, SMS interception, and UI automation via HTML overlays impersonating banking and cryptocurrency apps. For screen control, operators deploy a Go program that uses minicap and minitouch (on Android versions below 14) for undetected, permission-prompt-free screen streaming and synthetic taps, falling back to screencap at roughly five frames per second with a visible recording indicator on Android 14+ where minicap/minitouch no longer function without detection. Notably, the Go control program keeps running after the victim uninstalls the visible app, persisting until the device reboots; the two malicious components also mutually reinstall one another if either is removed, and the malware actively intercepts and blocks uninstall-confirmation dialogs.

To evade hash-based antivirus detection, the console can rebuild the distributed APK on a schedule (e.g., hourly), producing a new file hash from the same underlying malware each time. Anti-analysis measures include APK container tampering, an artificially bloated ~61MB AndroidManifest.xml, and invalid DEX pseudo-instructions intended to break static-analysis tooling.

The newest capability, introduced with Panda Workshop V6 in September 2026, has the console call Google's Gemini AI model against the SMS text and fake-overlay-captured credentials harvested from each infected phone to estimate that victim's bank balance, sorting devices into high-value and mid-value buckets so operators can prioritize manual follow-on fraud on the phones most worth their time -- Gemini is used for victim triage, not for automating the theft itself. Separately, RatHat also calls Gemini directly from the infected device at runtime, serializing the live Android Accessibility tree to XML and sending it to the model to determine where to tap when hard-coded UI automation fails across different device manufacturers, OEM skins, and Android versions -- solely to keep the wireless-debugging setup functioning across device diversity. Zimperium's concurrent, overlapping analysis (published September 16, 2026 by researchers Gianluca Braga, Vishnu Pratapagiri, and Fernando Ortega) documents the same on-device technique in more general terms: RatHat serializes the Accessibility tree and asks an AI assistant for tap/scroll/read instructions rather than following a hardcoded script, and the researchers attribute the malware to China-nexus operators after finding LLM prompts written in simplified Chinese in the sample set. Zimperium also reports distribution via malvertising, SMS, and phishing sites hosting APKs outside Google Play.

This on-device LLM-driven UI automation technique was first documented in Android malware by ESET in February 2026 in a distinct but related family, PromptSpy (an evolution of VNCSpy, first seen on VirusTotal from Hong Kong on 2026-01-13), which used Gemini prompts plus an XML dump of on-screen UI elements to keep itself pinned in the recent-apps list for persistence, and which also carried simplified-Chinese debug strings and targeted Argentina via a dedicated distribution site (mgardownload[.]com) using a fake JPMorgan Chase ('MorganArg') dropper. Neither Cleafy nor Zimperium disclosed a specific victim count, named targeted banks, or a named threat-actor group for RatHat; the Chinese-language attribution is based on artifact language only.

MITRE ATT&CK techniques used in TL-2026-2743

Defense Evasion

T1406 Obfuscated Files or Information; T1629.001 Prevent Application Removal; T1633 Virtualization/Sandbox Evasion; T1655 Masquerading; T1655.001 Masquerading: Match Legitimate Name or Location

Credential Access

T1417.001 Keylogging; T1417.002 GUI Input Capture; T1453 Abuse Accessibility Features

Discovery

T1426 System Information Discovery

Collection

T1429 Audio Capture; T1512 Video Capture; T1513 Screen Capture; T1517 Access Notifications; T1636.003 Protected User Data: Contact List; T1636.004 SMS Messages

Command and Control

T1437.001 Web Protocols; T1544 Ingress Tool Transfer; T1572 Protocol Tunneling; T1663 Remote Access Software

defense-evasion

T1516 Input Injection

Persistence

T1541 Foreground Persistence; T1577 Compromise Application Executable

Resource Development

T1583.001 Acquire Infrastructure: Domains

Execution

T1623.001 Unix Shell

Privilege Escalation

T1626 Abuse Elevation Control Mechanism

Initial Access

T1660 Phishing

Affected products and versions in RatHat Android RAT

  • Google — Android
    Vulnerable versions: Android < 14 (minicap/minitouch enable undetected screen streaming and synthetic tap injection without permission prompts); Android 14+ (falls back to screencap at ~5 fps with a visible recording indicator; wireless-ADB shell abuse via Accessibility-service still functions)

Remediation for RatHat Android RAT

Immediate actions

  • Block the documented RatHat C2 domains and IP (admin.chunhuating[.]best, admin.xiongmaocs[.]pics, admin.rathat[.]live, 8.231.120[.]246) and download URLs (dramaspoolcoa[.]com/en.html, rathat[.]me) at DNS/perimeter
  • Enforce installation from Google Play only; block sideloading of APKs from SMS links, ad redirects, and third-party 'app store' pages
  • Audit and restrict which apps hold Accessibility-service permissions on managed Android fleets; alert on newly granted Accessibility access followed by Developer Options / Wireless Debugging being enabled
  • For infected devices, uninstall via Safe Mode (third-party apps disabled) and factory-reset if the malware resists removal, then perform a full device reboot to clear any surviving Go-agent processes

Workarounds

  • Disable Wireless Debugging (Settings > Developer Options) when not actively used for legitimate development
  • Keep Google Play Protect enabled; it provides automatic protection against known RatHat/PromptSpy variants

Longer-term hardening

  • Deploy mobile threat defense (MTD) / EDR with behavioral detection for Accessibility-service abuse, wireless ADB pairing activity, and minicap/minitouch-style screen-streaming behavior
  • Monitor for hourly-cadence APK hash churn against known malware-family behavioral signatures rather than relying on static hash blocklists
  • Implement mobile banking app runtime protections (overlay/anti-screen-capture detection, root/ADB-debug detection) to detect when wireless debugging is active
  • Track emerging on-device and console-side LLM API abuse (Gemini, other GenAI APIs) as a detection signal in mobile threat intel feeds

Timeline of RatHat Android RAT

  • Fisher-branded RatHat console active (through February 2026), C2 admin.rathat[.]live, download URL rathat[.]me/app-release-rat-hat-live.apk; earliest sample hash f83357b2d47c7d38ee53943373961211 observed
  • VNCSpy, the predecessor to the related on-device-LLM Android malware family PromptSpy, first appears on VirusTotal from Hong Kong
  • February 2026 campaign uses a StripChat-themed decoy app with the Fisher panel (exact day not stated, first of month used).
  • ESET discloses PromptSpy, the first documented Android malware to call Google Gemini at runtime (for recent-apps persistence), targeting Argentina; RatHat Fisher-era sample 8fdc21e25097a46528211274e54330e1 also dated to this period
  • RatHat console rebuilt and rebranded 'BlackCat Remote Control Management'; Cleafy begins tracking console deployments from this point, eventually documenting nearly 100 instances; C2 IP 8.231.120[.]246 observed
  • Panda Workshop V5 deployments begin (May-August 2026): TOTP 2FA for operators, an AI balance widget and an API namespace restructure (exact day not stated, first of month used).
  • RedHook Android malware adds wireless-ADB abuse for computer-free shell access, part of the same technique trend RatHat uses
  • Panda Workshop V5 console version deployed, C2 admin.xiongmaocs[.]pics; ToxicPanda 2.0 separately documented using the same wireless-ADB abuse technique with an expanded 167-command set
  • Zimperium zLabs (Gianluca Braga, Vishnu Pratapagiri, Fernando Ortega) publishes overlapping RatHat analysis, documenting the three-component infection chain and attributing the malware to China-nexus operators based on simplified-Chinese LLM prompts found in samples
  • Panda Workshop V6 console deployed with Gemini AI-driven victim bank-balance estimation and high/mid-value triage; C2 admin.chunhuating[.]best; sample hash 116346cace7f00ba557034b534d40791; download URL dramaspoolcoa[.]com/en.html
  • Cleafy's research is publicly reported by The Hacker News, disclosing nearly 100 documented RatHat console deployments since April 2026 and the Gemini-driven victim-prioritization feature
  • Infosecurity Magazine and other outlets report the Cleafy findings on the Gemini-assisted victim scoring.

Update history for TL-2026-2743

Sources cited for RatHat Android RAT

More in malware

Detection coverage for TL-2026-2743

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2743 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats