A September 28, 2026 analysis by security firm Cleafy says RatHat’s latest Android malware console uses Gemini to estimate potential victims’ bank balances from SMS collected on infected devices, then sort devices into high- and mid-value groups for operator attention. Cleafy says the samples it analyzed did not use Gemini to move money.
RatHat’s reported Gemini scoring function
The console-side feature estimates bank balances from messages the malware has already collected. It then groups infected devices by estimated value, helping operators decide which ones to prioritize. That is a sorting function—not Gemini carrying out a financial transaction.
Gemini on the infected device
RatHat has a separate, on-device use for Gemini. When its stored automation fails to handle an unfamiliar interface, the malware can send screen-structure information to Gemini to help locate controls or interpret text. This navigation assistance is distinct from the console’s balance estimates and device rankings.
Console changes and the deployment estimate
Cleafy describes three recent console generations built from a common codebase: BlackCat Remote Control Management, Panda Workshop V5, and Panda Workshop V6. Earlier RatHat samples were associated with a separate console called Fisher. The operator console changed across these generations, while the implant itself remained broadly similar from late 2025 through September 2026.
Cleafy identified nearly 100 separate console deployments since April 2026 and associated the observed activity with Europe, Latin America, and Southeast Asia. The figure is a count of console deployments, not infected phones or individual victims.
Android control context
Cleafy says RatHat obtains Android shell-level access after Accessibility access is granted and wireless debugging is enabled. It also reports that RatHat’s minicap and minitouch screen-control method does not work on Android 14 and later.