RatHat Android malware uses Gemini AI to target victims
Operators of the RatHat Android banking malware are using a web console that employs Google's Gemini AI model to estimate victims' bank balances from stolen SMS messages. This allows attackers to rank infected devices by potential value, prioritizing which victims to target. The attack infrastructure, including its command-and-control panel, has rapidly evolved and supports a malware-as-a-service model, facilitating hundreds of deployments and parallel campaigns across multiple regions.
- Gemini AI used to estimate and rank victim bank balances
- Console can build and deploy new Android malware samples
- Nearly 100 console deployments observed since April 2026
- RatHat infrastructure follows a malware-as-a-service model
- Panel updates include 2FA, phishing builder, role-based access
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
New Spectre BTR attack exposes Linux root password hashes
Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from…