News / Cybersecurity
RatHat: The Android Malware That Uses Gemini to Target High-Value Victims Published on 29 September 2026 by Christ-loisele (2 min read)
Researchers at Cleafy reveal that the RatHat malware exploits Google’s Gemini AI to estimate victims’ bank balances by intercepting their SMS messages. This automated approach allows attackers to prioritize targets, according to an analysis of nearly 100 deployments since April 2026.
Video: RatHat Android Malware Uses AI to Control Your Phone | Banking Credentials & OTPs at Risk (CyberRakshakLabs, YouTube)
AI-Based Targeting
The RatHat malware, targeting Android devices, now uses Google’s Gemini API to analyze intercepted banking messages and estimate victims’ balances. According to Cleafy, this feature allows operators to categorize infected devices into two groups: high-value and medium-value , based on their estimated assets. This method, integrated into the latest version of the control console (Panda Workshop V6), replaces a previous system where multiple AI providers were offered to attackers.
RatHat’s latest Android malware console uses Gemini to estimate potential victims’ bank balances from SMS collected on infected devices
Illustration: Lawing Tech
An Evolving Console to Evade Detection
Since April 2026, RatHat’s console has gone through three generations, with major updates to bypass security tools. The current version, Panda Workshop V6, allows operators to automatically recompile the malware to alter its fingerprint (hash) and avoid signature-based blocks, as explained by Cleafy. The malware also exploits Accessibility permissions to enable remote debugging (ADB) and gain full control over the device, including through tools like minicap and minitouch to simulate user interactions without raising alerts.
What This Changes Here
For businesses and government agencies in Benin and West Africa, where smartphone usage for banking transactions and public services is becoming widespread, this evolution of RatHat highlights two major risks. First, automated targeting via AI could encourage cybercriminals to focus attacks on mobile financial service users, particularly those using local banking apps or e-wallets. Second, the malware’s ability to dynamically rebuild itself makes it harder to detect using traditional security solutions, which are already under-resourced in many regional organizations.
Institutions should therefore strengthen audits of software permissions (such as Accessibility) and consider behavioral detection solutions, capable of identifying anomalies linked to the exploitation of Gemini or other AI tools by malware.
Sources