RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy hasΒ traced nearly 100 deploymentsΒ of that console since April 2
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy hasΒ traced nearly 100 deploymentsΒ of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.
The console stores what the malware collects from each phone,
π° Read the original article on The Hacker News
Originally published by The Hacker News. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.