Back to all news
Security

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

The Hacker News·September 28, 2026·1 min read
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish an Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026, fitting a malware-as-a-service model where each customer runs a separate copy. The console stores what the malware collects from each phone.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store