RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
Summary
The RatHat Android banking trojan is controlled via a web console that operators use to identify higher-value victims, according to security company Cleafy. This malware-as-a-service model involves separate console copies for each customer, with the console storing data collected from infected phones.
IFF Assessment
The discovery of a new banking trojan utilizing advanced techniques to identify high-value targets represents a threat to users and financial institutions.
Defender Context
This report highlights the evolving sophistication of Android malware, particularly the use of AI like Gemini to profile and target high-value victims. Defenders should be aware of advanced banking trojans and the potential for these threats to adapt using AI for more effective phishing and financial fraud campaigns.