< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News• 2026-09-28T23:08:33+05:30

RatHat Android Malware Leverages Google Gemini AI for High-Value Victim Identification

RatHat Android malware uses Google's Gemini AI to estimate victims' bank balances and prioritize high-value targets, leveraging a malware-as-a-service model. The malware employs AI for victim classification and advanced evasion techniques, including stealthy screen capture and persistent reinstallation capabilities.

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.

The console stores what the malware collects from each phone,

Read original article

*** END OF TRANSMISSION ***