Security1 publisher2 min readPublished
RatHat operators use Gemini to rank Android victims by estimated bank balance
RatHat's malware console now feeds stolen texts to Google's Gemini to estimate each victim's bank balance and rank who to rob first, security firm Cleafy says. Cleafy has traced nearly 100 deployments since April 2026 and found nothing that moves money.
The Watch · Security desk

What happened
- Cleafy calls RatHat a malware-as-a-service operation, with each customer running a separate copy of the web console that controls the infected phones.
- The console can rebuild the trojan on an hourly schedule, minting a fresh file from the same code each time so that hash-based detection keeps missing it.
- After the victim grants Accessibility access, the app opens an Android Debug Bridge shell that runs as the shell user UID 2000, giving the operator powers beyond the app's own.
- A Go program keeps running after the victim deletes the app, until the phone restarts, and Zimperium found it can reinstall the app and switch Accessibility back on.
- Zimperium reported RatHat spreads through text messages and online ads that funnel targets to third-party download sites.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability A crew no longer sifts thousands of intercepted texts by hand; Gemini scores each phone so operators spend their time only on the accounts likely to pay out.
- constraint The near-100 figure counts console installs, not phones, so it measures the operators' tooling and not the number of people at risk.
- exposure Because neither firm published a clean-removal procedure, an infected user has no vendor-backed way to confirm the phone is actually clear.
- precedent Scoring victims with a commodity model keyed through a public developer portal lowers the bar for the next crew to bolt AI triage onto its own console.
Cleafy said the first console version let operators pick among several AI providers and fire a Telegram alert when a phone's score crossed a set level. [26] The current version works only with Gemini and sends operators to Google AI Studio for an API key. [27]
The model works from the text messages and stolen login details the malware has already collected. [4] Cleafy said its role is "deciding which victims are worth an operator's time." [7] None of the samples the firm analyzed used the model to move money. The cash still leaves through the fake login screens the malware paints over banking apps. [6][4]
Every version of the console is also a build tool. An operator can assemble the malware, wrap it in a harmless-looking app, sign it, and push it to Amazon S3 or a web server without touching the hosting. [11] The latest version ships templates for fake download pages, one of them called Google Store. [13]
Cleafy found the deployments by fingerprinting the console's page titles and web code. Neither its report nor Zimperium's says how many victims there are. [23][24] Nearly half the IP addresses it observed sit on one Singapore-registered network, AS4907. [25]
The minicap and minitouch tools the Go component uses to stream the screen without a permission prompt do not run on Android 14 or later. Those phones fall back to the app's own capture, which asks the victim for permission and shows a recording icon. [18][19] Cleafy described a backup method using a tool called screencap at about five frames per second but did not say which Android versions it covers. [20]
The console also caps operator accounts and hides sections from non-admins, which Cleafy said only makes sense if the users are customers the developers do not fully trust. [28]
What to watch
- Whether Google restricts API keys or AI Studio access once abuse tied to RatHat is confirmed.
- Whether Cleafy or Zimperium publish a removal procedure for the persistent Go component.
- Whether other malware-as-a-service consoles adopt Gemini-only victim scoring.