RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Swati KhandelwalSep 28, 2026Mobile Security / Artificial Intelligence RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps. Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups. Nothing in the…
Original source: thehackernews.com