RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Summary

The RatHat Android banking trojan is controlled via a web console that operators use to identify higher-value victims, according to security company Cleafy. This malware-as-a-service model involves separate console copies for each customer, with the console storing data collected from infected phones.

IFF Assessment

FOE

The discovery of a new banking trojan utilizing advanced techniques to identify high-value targets represents a threat to users and financial institutions.

Defender Context

This report highlights the evolving sophistication of Android malware, particularly the use of AI like Gemini to profile and target high-value victims. Defenders should be aware of advanced banking trojans and the potential for these threats to adapt using AI for more effective phishing and financial fraud campaigns.

Read Full Story →