RatHat Android Trojan C2 Panel Evolves into MaaS Model

The infrastructure behind the RatHat Android banking trojan is rapidly maturing into a malware-as-a-service operation, with an evolving command-and-control panel that can build new malware samples, manage infected devices at scale and use artificial intelligence to rank high-value victims across nearly 100 observed deployments since April 2026.[1][4]

Researchers at Cleafy report that successive versions of the RatHat web console have shifted from simply issuing commands to compromised phones to acting as a full-fledged builder and operations hub, letting operators generate customized Android packages, push configuration updates and monitor live device telemetry from a single pane of glass.[1] The latest iteration integrates Google’s Gemini model to analyze SMS messages harvested from infected devices, estimate each victim’s likely bank balance and automatically sort phones into high-value and mid-value tiers, streamlining target selection without requiring operators to manually review every compromised handset; Cleafy stresses that the AI is used for prioritization rather than executing fraudulent transactions itself.[1][4]

Behind that console sits a multi-component architecture consisting of a malicious Android application, a native Go agent and an FRP reverse-proxy client, all coordinated by the C2 panel.[9][11] The Go agent runs with shell-level privileges via the local ADB context, where it can exempt the malware from battery optimization, disable or uninstall other apps—including mobile security tools—and retrieve FRP configuration from the server.[9][11] The FRP client then maintains a persistent, encrypted reverse tunnel back to the C2 infrastructure, ensuring operators retain remote access and telemetry even if the visible Android app is removed from the device.[9][5]

Technical analyses from Zimperium zLabs and other researchers highlight RatHat’s use of generative AI to navigate Android user interfaces in real time, serializing the live Accessibility tree to XML and sending it to a cloud assistant that returns tap coordinates and navigation commands such as “SCROLL_DOWN.”[7][11][14] Separate threat intelligence notes describe how the malware abuses Accessibility services to unlock Developer Options, enable Wireless Debugging and autonomously pair with the local ADB daemon, staging native Go-based daemons with shell-level privileges that persist outside the normal app lifecycle and can silently reinstall the trojan after deletion.[3][12][8] Those daemons support hardware-level keylogging, MediaProjection screen capture and lock-screen PIN and pattern theft, giving operators the ability to reconstruct credentials and perform full device takeover once the C2 panel flags a victim as sufficiently valuable.[3][12][13][14]

Multiple threat intelligence vendors assess RatHat as operated by China-based threat actors and note that it is being distributed predominantly via smishing and malvertising campaigns impersonating banks and other trusted brands.[2][4][12] Reports describe how the malware dynamically changes its icon and app label to mimic legitimate services, luring users into entering credentials and multi-factor authentication codes that are then captured and exfiltrated over HTTP and WebSocket channels to the C2 backend.[5][11][14] Once installed, RatHat can harvest SMS messages, intercept one-time passwords, enumerate installed applications and log keystrokes—including URLs typed into browser address bars—providing rich data for the AI-driven scoring system exposed in the panel.[11][8][15]

Some intelligence feeds link RatHat campaigns to a vulnerability tracked as CVE-2026-91843, though public details and vendor advisories on that flaw remain limited and major scoring platforms have yet to be widely cited in reporting.[2][12][8] In the absence of clear patch guidance, mobile defenders are focusing on behavioral indicators highlighted by researchers, including unexpected Wireless Debugging toggles enabled by non-admin apps, unusual Accessibility requests from newly installed software and signs of FRP-based reverse tunnels originating from user devices.[3][5][7] Organizations are being urged to harden mobile fleets with endpoint protection that can monitor for ADB misuse and Accessibility abuse, restrict side-loading, and pair technical controls with customer education about sophisticated smishing campaigns that deliver RatHat and similar AI-enhanced banking trojans.[5][7][13][15]

References

  1. RatHat’s Evolving C2 Panel Points to Malware-as-a-Service Model
  2. RatHat Android Trojan Exploits AI and ADB
  3. RATHAT (Zimperium zLabs Sep 18, assessed China-based): Android spyware that self-pairs to ADB – Accessibility grant unlocks Developer Options, enables Wireless Debugging, reads the 6-digit pairing code off the screen, stages shell-privilege native daemons OUTSIDE the app lifecycle that silently reinstall after uninstall, plus an FRP reverse tunnel; drives the screen with a live cloud-LLM loop over the serialized Accessibility tree (LLM asked only benign localization questions = AI calls blend into normal traffic); hardware-level on-screen keylogger, MediaProjection capture, lock-screen PIN capture; 4 named pipeline-killer anti-analysis tricks (directory-declared files, ZIP encryption-bit entries, 0x9999 manifest chunks, invalid element_width opcodes) – ‘analysis timed out’ != clean; hunt Wireless-Debugging toggles by non-admin apps + a11y-usage co-timed with pairing dialogs
  4. mobile security — Latest News, Reports & Analysis
  5. Cyware Daily Threat Intelligence – September 17, 2026
  6. RatHat: A Live AI Agent Controls Compromised Android Devices
  7. RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs, and MFA Codes
  8. New ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
  9. RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
  10. RatHat Android Malware Uses AI and ADB Self-Pairing
  11. RatHat Android Trojan Uses AI for Automation
  12. New Android malware uses AI to steal bank logins and PINs
  13. RatHat Android Trojan Uses AI for Automation – Live Threat Intelligence – Threat Radar | OffSeq.com

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply