RatHat operators leverage Google's Gemini AI to prioritise high-value victims among infected Android devices, according to research published by Cleafy. The threat actors deploy a web-based command-and-control console that manages the Android banking trojan across multiple customer instances, each running independent copies of the malware infrastructure.
Cleafy identified nearly 100 distinct deployments of the RatHat console since April 2024, indicating the malware operates under a malware-as-a-service model. Each deployment serves a separate customer, allowing multiple threat actors to operate the same banking trojan independently through the shared infrastructure.
The RatHat banking trojan targets Android devices and functions as a credential stealer and financial transaction interceptor. The web console aggregates data harvested from compromised phones, then feeds this information to Gemini for analysis. The AI system identifies which victims possess the highest financial value based on transaction histories, account balances, and banking relationships. This automated victim prioritisation allows RatHat operators to concentrate their manual effort on accounts worth the most money, improving operational efficiency.
The use of Gemini represents a notable evolution in malware operations. Rather than relying solely on human analysts to wade through thousands of compromised devices, RatHat operators outsource the labour-intensive triage process to an AI model. Gemini processes victim data and scores accounts by financial value, enabling operators to focus social engineering, credential harvesting, or transaction manipulation on the highest-impact targets.
This tactic underscores a broader trend in which cybercriminals adopt legitimate AI services for malicious purposes. Large language models like Gemini offer cheap, scalable analysis that would require hiring significant staff otherwise. Malware operators exploit the ease of API access and the lack of content filtering in many use cases.
The malware-as-a-service distribution model compounds the risk. By selling access to separate console instances, RatHat's operators generate revenue from multiple threat actors simultaneously. Each customer operates their own isolated deployment, reducing operational visibility and making law enforcement takedowns more complex. Customers pay for the trojan and console access, then target victims within their geographic region or industry vertical.
RatHat primarily targets users in specific regions, though Cleafy did not name the countries. The banking trojan intercepts SMS messages, captures credentials through overlay attacks, and monitors financial applications. Once a device falls under RatHat's control, operators maintain persistence through background processes and resistance to removal.
The Gemini integration reveals how threat actors progressively adopt mainstream technology to automate and improve attack workflows. Security teams defending against Android banking trojans must now assume attackers prioritise victims based on AI-driven financial profiling. Organisations cannot rely on low-profile accounts to remain unmolested by determined attackers.
Cleafy recommended immediate patching of Android devices, disabling sideloading of applications, and enforcement of mobile device management policies. Users should avoid installing banking applications outside official app stores and enable biometric authentication where available. Financial institutions should implement behavioural analytics to detect anomalous transaction patterns consistent with RatHat activity.
