Interestana
Home/News/RatHat Malware Console Leverages Gemini for Victim Identification
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

RatHat Malware Console Leverages Gemini for Victim Identification

RatHat Malware Console Leverages Gemini for Victim Identification

The operators of the RatHat Android banking trojan have integrated Google's Gemini artificial intelligence model into their web console to enhance their ability to identify and target higher-value victims. Security company Cleafy reported this development, detailing how the malware-as-a-service model allows each customer to operate a distinct copy of the trojan and its associated control console. Cleafy has observed nearly 100 deployments of this console since April 2026, indicating a significant operational footprint.

The RatHat console serves as the central command and control hub for infected Android devices. It collects sensitive data from compromised phones, including banking credentials, personal information, and other financial details. By employing Gemini, the malware operators can now analyze this collected data more effectively. The AI's advanced natural language processing and data analysis capabilities enable the system to sift through vast amounts of information, identifying patterns and characteristics indicative of users with greater financial resources or access to more lucrative accounts. This allows the attackers to prioritize their efforts and focus on exploiting the most profitable targets.

This strategic use of AI by malware developers represents a growing trend in the cybercrime landscape. Advanced AI models like Gemini, originally designed for legitimate applications such as content creation, data analysis, and customer service, are being repurposed by malicious actors to improve the efficiency and effectiveness of their attacks. The ability of Gemini to understand context, identify anomalies, and make predictions based on complex datasets makes it a powerful tool for cybercriminals seeking to automate and optimize their operations. The integration of such sophisticated AI into malware control systems poses a significant challenge for cybersecurity professionals, requiring new approaches to threat detection and mitigation.

Cleafy's analysis suggests that the RatHat trojan operates within a malware-as-a-service (MaaS) framework. In this model, the developers create and maintain the malware and its infrastructure, then lease it to other cybercriminals who act as customers. Each customer typically receives a unique instance of the control console, allowing them to manage their own campaigns independently. This MaaS approach lowers the barrier to entry for aspiring cybercriminals, as they do not need to possess the technical expertise to develop malware from scratch. The continued evolution of RatHat, including its adoption of advanced AI for victim profiling, underscores the persistent and adaptive nature of mobile banking trojans.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next