Full Report
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
Analysis Summary
# Tool/Technique: RatHat Android Banking Trojan & Control Console
## Overview
RatHat is a sophisticated Android banking trojan operated under a Malware-as-a-Service (MaaS) model. It utilizes a web-based command-and-control (C2) console that functions as both a management interface and a build tool. Notably, recent versions have integrated Large Language Models (Google Gemini) to automate the valuation of victims by analyzing intercepted messages to estimate bank balances.
## Technical Details
- **Type:** Malware Family / Banking Trojan / MaaS Framework
- **Platform:** Android
- **Capabilities:** Overlay attacks, SMS interception, keylogging, automated ADB exploitation, screen streaming, and AI-driven victim profiling.
- **First Seen:** Late 2025 (Initial versions); April 2026 (New console versions).
## MITRE ATT&CK Mapping
- **[TA0030 - Persistence]**
- [T1544 - Command and Scripting Interpreter] (Abuse of ADB shell)
- **[TA0031 - Privilege Escalation]**
- [T1418 - Abuse Accessibility Services]
- **[TA0033 - Credential Access]**
- [T1411 - Input Injection] (Overlay attacks)
- [T1636.004 - SMS Messages]
- **[TA0037 - Command and Control]**
- [T1573 - Encrypted Channel] (Reverse tunnels via Go program)
- **[TA0035 - Collection]**
- [T1513 - Screen Capture] (Using minicap/screencap)
## Functionality
### Core Capabilities
- **Automated Builder:** The console allows operators to build, obfuscate, and sign malware samples. It can automatically rebuild files (e.g., hourly) to rotate hashes and evade signature-based detection.
- **Automated Deployment:** Publishes finished malicious APKs directly to Amazon S3 or web servers.
- **ADB Exploitation:** Abuses Android Accessibility Services to enable "Wireless Debugging," read pairing codes, and establish a shell via Android Debug Bridge (ADB) with UID 2000 permissions.
- **Overlay Attacks:** Generates fake login screens over legitimate banking apps to steal credentials.
### Advanced Features
- **AI Victim Profiling (Gemini Integration):** Uses Google Gemini to scan intercepted SMS/messages, estimate the victim's bank balance, and categorize them as "high-value" or "mid-value."
- **Stealth Screen Streaming:** Utilizes a Go-based program with `minicap` and `minitouch` to stream screens and inject taps without triggering the standard Android recording icon or permission prompts (on versions prior to Android 14).
- **Persistence Mechanism:** The Go-based reverse tunnel survives the uninstallation of the main malware app, persisting until a device reboot. It can also be used to silently reinstall the app and re-enable Accessibility settings.
## Indicators of Compromise
- **File Names:** Harmless-looking apps (e.g., system updates or utility apps), fake "Google Store" pages.
- **Network Indicators:**
- `AS4907` (Singapore-registered network commonly used for hosting).
- Infrastructure involving Amazon S3 buckets for malware distribution.
- **Behavioral Indicators:**
- Unauthorized requests for Accessibility Services.
- Unexpected activation of Wireless Debugging/ADB settings.
- Outbound reverse tunnel connections (Go-based binaries).
## Associated Threat Actors
- **MaaS Operators:** The specific developers are unidentified, but the console is distributed to multiple sub-customers/affiliates (traced to nearly 100 deployments).
## Detection Methods
- **Signature-based:** Traditional hash-based detection is difficult due to the console's automated rebuilding/polymorphic features.
- **Behavioral Detection:** Monitoring for apps that request Accessibility Services and immediately attempt to toggle Developer Options/ADB.
- **Network Monitoring:** Detecting persistent reverse tunnels or connections to known malicious hosting providers on AS4907.
## Mitigation Strategies
- **Prevention:** Disable "Developer Options" and "USB/Wireless Debugging" on production devices.
- **Hardening:** Upgrade devices to Android 14 or later, as these versions implement stricter controls over screen capture notifications and tool compatibility (e.g., blocking `minicap`).
- **Policy:** Restrict the installation of apps from "Unknown Sources" and use Mobile Threat Defense (MTD) solutions to monitor for Accessibility Service abuse.
## Related Tools/Techniques
- **Fisher:** The predecessor console used in late 2025/early 2026.
- **BlackCat Remote Control Management:** The first iteration of the new console series.
- **Panda Workshop (V5 & V6):** The current iterations of the RatHat C2 framework.
- **Minicap/Minitouch:** Open-source tools repurposed for stealthy screen interaction.