New research from Cleafy Labs details how the RatHat Android banking malware operation has evolved into a broader Malware-as-a-Service platform, with nearly 100 C2 deployments, automated APK building and signing, shell-level device control, and Gemini used both to navigate unfamiliar Android interfaces and help operators prioritize victims.
Ted Miracco, CEO of Approov:
“Modern mobile threats have evolved from basic signature-based malware into AI-augmented automation engines. Traditional endpoint security and static app shielding are no longer sufficient because attackers now deploy malware that uses artificial intelligence to dynamically navigate unfamiliar user interfaces, exploit device-level debug bridges, and bypass or escalate operating system permission models.
“Defending against this new generation of AI-driven threats requires mobile developers and financial institutions to adopt a zero-trust model built directly into their mobile apps and API ecosystems. When attackers leverage AI to adapt to defensive controls on the fly, static security measures will inevitably fail. Organizations must shift their focus from looking for known malware signatures to continuously enforcing dynamic environment trust and securing their backend APIs at every transaction.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity at Suzu Labs:
“Android fragmentation used to be an attacker tax. Every manufacturer skin, language, and banking app version meant another brittle tap script to maintain. RatHat is using Gemini to turn that tax into a model call.
“That changes the economics of mobile malware. The implant can inspect a live screen when its static automation fails and ask where the next control is. The cost shifts from maintaining a separate playbook for every device to handling exceptions at runtime.
“Cleafy’s mapping of nearly 100 command-and-control (C2) deployments shows why that matters. The panel builds, signs, repackages, and distributes Android application package (APK) samples, while the same operation uses Gemini to read short message service (SMS) messages and estimate victims’ bank balances. An affiliate gets both a malware factory and a compatibility layer.
“Code generation can speed up the first version of a campaign. Runtime adaptation reduces the maintenance work that determines whether the campaign keeps working across real phones. Gemini is being used as middleware between a messy Android ecosystem and a repeatable criminal service.
“Defenders should measure that change in attacker economics. I would want mobile detection to flag model-assisted navigation combined with Accessibility abuse, wireless debugging, and local Android Debug Bridge (ADB) pairing. A bank can validate its app and the customer’s login while missing the runtime loop driving the session.
“A valid banking session can still be an attacker-controlled transaction surface.”
Excellent. A new banking trojan to be aware of. Which means you need to come up with a defence for this as well. And quickly.
Related
This entry was posted on September 30, 2026 at 4:23 pm and is filed under Commentary with tags Tojan. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
RatHat banking malware exposed in new research
New research from Cleafy Labs details how the RatHat Android banking malware operation has evolved into a broader Malware-as-a-Service platform, with nearly 100 C2 deployments, automated APK building and signing, shell-level device control, and Gemini used both to navigate unfamiliar Android interfaces and help operators prioritize victims.
Ted Miracco, CEO of Approov:
“Modern mobile threats have evolved from basic signature-based malware into AI-augmented automation engines. Traditional endpoint security and static app shielding are no longer sufficient because attackers now deploy malware that uses artificial intelligence to dynamically navigate unfamiliar user interfaces, exploit device-level debug bridges, and bypass or escalate operating system permission models.
“Defending against this new generation of AI-driven threats requires mobile developers and financial institutions to adopt a zero-trust model built directly into their mobile apps and API ecosystems. When attackers leverage AI to adapt to defensive controls on the fly, static security measures will inevitably fail. Organizations must shift their focus from looking for known malware signatures to continuously enforcing dynamic environment trust and securing their backend APIs at every transaction.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity at Suzu Labs:
“Android fragmentation used to be an attacker tax. Every manufacturer skin, language, and banking app version meant another brittle tap script to maintain. RatHat is using Gemini to turn that tax into a model call.
“That changes the economics of mobile malware. The implant can inspect a live screen when its static automation fails and ask where the next control is. The cost shifts from maintaining a separate playbook for every device to handling exceptions at runtime.
“Cleafy’s mapping of nearly 100 command-and-control (C2) deployments shows why that matters. The panel builds, signs, repackages, and distributes Android application package (APK) samples, while the same operation uses Gemini to read short message service (SMS) messages and estimate victims’ bank balances. An affiliate gets both a malware factory and a compatibility layer.
“Code generation can speed up the first version of a campaign. Runtime adaptation reduces the maintenance work that determines whether the campaign keeps working across real phones. Gemini is being used as middleware between a messy Android ecosystem and a repeatable criminal service.
“Defenders should measure that change in attacker economics. I would want mobile detection to flag model-assisted navigation combined with Accessibility abuse, wireless debugging, and local Android Debug Bridge (ADB) pairing. A bank can validate its app and the customer’s login while missing the runtime loop driving the session.
“A valid banking session can still be an attacker-controlled transaction surface.”
Excellent. A new banking trojan to be aware of. Which means you need to come up with a defence for this as well. And quickly.
Share this:
Like this:
Related
This entry was posted on September 30, 2026 at 4:23 pm and is filed under Commentary with tags Tojan. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.