RatHat's malware console now feeds stolen texts to Google's Gemini to estimate each victim's bank balance and rank who to rob first, security firm Cleafy says. Cleafy has traced nearly 100 deployments since April 2026 and found nothing that moves money.
Reality
- Evidence55
- Adoption25
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Zimperium says the Android banking Trojan now abuses Accessibility to switch on wireless debugging and run commands through the ADB daemon. The target list is the smaller half of the story.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives55
- Confidence64
Zimperium's September 9 write-up describes an Indonesian-linked family that encrypts files and streams the screen at once, resolves its command server through a GitHub repository, and loses most of its encryption reach on Android 10.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives30
- Confidence65
Zimperium says RatHat uses an accessibility grant to switch on Wireless Debugging and read its own 6-digit pairing code, leaving native daemons at shell privilege that keep answering after the app is removed.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence66
The Georgia Tech corpus says the handset belongs to the attacker while Regulation E says the loss belongs to the bank, which makes every extra authentication factor pushed to that same phone a purchase with no yield.
Reality
- Evidence72
- Adoption68
- Hype gap+12
- Incentives66
- Confidence60
Island says the kit relays Microsoft 365 sign-ins behind genuine Docusign envelopes and legitimate Microsoft or Google redirects, leaving sender reputation nothing to grade.
Reality
- Evidence60
- Adoption58
- Hype gap+18
- Incentives74
- Confidence62
Zimperium's 2026 heist report tracks 34 malware families against 1,243 financial brands. The capability mix has moved from stealing credentials to owning the handset and encrypting it.
Reality
- Evidence38
- Adoption54
- Hype gap+32
- Incentives82
- Confidence44
ThreatFabric says the Android trojan hands collected data to nearby infected devices over Wi-Fi Direct or Bluetooth until one can reach command and control.
Reality
- Evidence48
- Adoption40
- Hype gap+18
- Incentives70
- Confidence52