Story thread · 2 reports / 2 sources

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

thehackernews.com · 23h · first report

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

The coverage

  1. RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model

    infosecurity-magazine.com · 2h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.