cybersecuritynews.com
RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots.
Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia.
Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three generations of the malware’s operator panel between April and September 2026.
Samples from late 2025, February 2026 and current campaigns retained a similar design, while the infrastructure behind them changed substantially. Earlier campaigns used cryptocurrency trading and adult entertainment decoys.
Cleafy said in a report shared with Cyber Security News (CSN) that nearly 100 separate deployments had appeared since April 2026.
RATHat Architecture (Source – Cleafy)
Licensing restrictions and parallel campaigns support a malware-as-a-service model, rather than proving one central group controls every deployment.
RATHat Android Malware
After receiving Accessibility access, RATHat navigates the phone’s settings, enables wireless debugging and reads the pairing code displayed on screen. It pairs with the local Android Debug Bridge service, gaining access as the shell user, identified by Android as UID 2000.
The pairing process relies on finding specific controls, but fixed instructions can fail on unfamiliar manufacturer interfaces, Android versions or languages. When that happens, the malware sends Gemini a structured description of the live interface and asks where to tap.
Gemini returns coordinates or short text that helps resolve an unfamiliar label. Requests go directly from the phone to Gemini Flash models using a key stored in the malware configuration, rather than passing through the attackers’ command server.
This resembles the adaptive navigation seen in Gemini assisted Android spyware that replaces rigid screen instructions with model responses.
The C2 Panels Observed (Source – Cleafy)
In RATHat, however, the observed device-side AI function specifically keeps the wireless-debugging pairing sequence working when ordinary text matching fails.
Once pairing succeeds, an operator can deploy a separate service written in Go with one click. It runs independently of the app, opens a local HTTP server on port 7912 and remains reachable through a reverse tunnel to the attacker’s infrastructure.
The service can capture screen content and inject touches using Android testing tools without the usual screen-recording prompt or indicator.
Cleafy noted that those tools do not work on Android 14 and later, leaving newer devices dependent on app-based capture with user consent.
Fraud Infrastructure
The command panel evolved from BlackCat into Panda Workshop V5 and V6. V5 introduced operator two-factor authentication and an AI balance-scoring widget, while V6 obscured its frontend code, added phishing download-page templates and consolidated AI settings around Gemini.
Operators can build, package, sign and publish malicious apps without leaving the console. Scheduled rebuilding produces fresh files while keeping the underlying implant unchanged, helping campaigns evade detection methods that depend on recognizing previously recorded file hashes.
Alongside remote control, the panel exposes stolen messages, credentials, contacts, photographs and files. Fake screens placed over targeted apps capture entered information.
Similar ToxicPanda wireless debugging abuse shows why this developer feature has become a concern beyond conventional credential theft.
A separate AI function analyzes collected SMS messages to estimate victims’ bank balances and rank devices by value. It helps operators select targets, rather than carrying out fraud itself.
Cleafy found no analyzed sample that used AI-guided navigation to complete a fraudulent transfer. Cleafy recommends monitoring activity executed as UID 2000, extending security checks beyond the application’s permissions and lifecycle.
Downloaded testing tools retain recognizable filenames in the temporary deployment directory, providing artifacts that investigators can examine during a suspected compromise.
The removal gap is important: deleting the visible app does not immediately stop the independent service, which survives until reboot. The research also warns that AI-assisted interface navigation could reduce the custom engineering needed for future automated banking attacks, although that broader capability was not demonstrated here.
Indicators of compromise (IoCs):-
Type Indicator Description Domain admin.chunhuating[.]best September 2026 command-and-control infrastructure, Panda Workshop V6. Domain admin.xiongmaocs[.]pics August 2026 command-and-control infrastructure, Panda Workshop V5. IPv4 8.231.120[.]246 April 2026 command-and-control infrastructure, BlackCat. Domain admin.rathat[.]live December 2025 and February 2026 command-and-control infrastructure, Fisher. URL https://dramaspoolcoa[.]com/en.html September 2026 delivery page. MD5 116346cace7f00ba557034b534d40791 September 2026 malware sample. URL https://rathat[.]me/app-release-rat-hat-live.apk December 2025 and February 2026 delivery URL. MD5 8fdc21e25097a46528211274e54330e1 February 2026 malware sample. MD5 f83357b2d47c7d38ee53943373961211 December 2025 malware sample. File name app-release-rat-hat-live.apk Android package filename appearing in the source’s delivery URL. File path /data/local/tmp Deployment directory for the native service and downloaded tools; not inherently malicious. File name minicap Legitimate Android testing tool abused for screen capture; not a unique malware indicator. File name minitouch Legitimate Android testing tool abused to inject touch events; not a unique malware indicator. File name screencap Android screen-capture utility used as a fallback; not a unique malware indicator. URI path /api/bin/arm64-v8a/minicap Example command-server path used to retrieve an architecture-specific screen-capture tool.
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM .
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions appeared first on Cyber Security News .