HackerFeeds

CyberSecurity News

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

The Hacker News
· September 28, 2026

AI summary

Security company Cleafy has been tracking the RatHat Android banking trojan, which is controlled by its operators through a web console. The console is used to manage infected phones and store collected data. Cleafy has identified nearly 100 deployments of this console since April 2026, indicating a malware-as-a-service model where each customer operates a separate instance. This model allows multiple customers to use the malware, with each running their own copy. The collected data from infected phones is stored in the console, potentially helping to identify higher-value targets.

Read the full article at The Hacker Newsthehackernews.com/2026/09/rathat-android-malware-console-uses.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.