As reported by The Hacker News, the operators behind RatHat — an Android banking trojan tracked across roughly 100 console deployments since April 2026 — have integrated Google's Gemini into their command-and-control workflow to triage infected phones by estimated financial value. This isn't another "AI wrote malware" story; it's something subtler and arguably more consequential: a malware-as-a-service (MaaS) operation using a legitimate LLM API as a revenue-optimization layer.
What's actually new here
Banking trojans have always done victim triage. They've always stolen SMS messages, captured credentials through overlay attacks, and shipped that data back to operators. What's new is the automation of the judgment step: rather than a human operator eyeballing stolen SMS alerts to estimate a target's balance, Gemini is asked to do it. The model then sorts infected devices into "high-value" and "mid-value" buckets. That classification drives which victims get live operator attention — and the rest get ignored.
This matters for two reasons. First, it scales operator attention. A MaaS customer paying for a console expects return on investment; AI-assisted triage lets one operator effectively service a larger pool of compromised devices by focusing only where the money is. Second, it normalizes the use of consumer-genAI APIs as back-office components of criminal infrastructure. Gemini is the visible example today, but the pattern is API-agnostic.
The ADB abuse deserves more attention than the AI angle
Lost in the "AI sorts victims" framing is a more technically significant detail: RatHat abuses Android's Accessibility Service to enable wireless debugging, read the on-screen pairing code, and connect to the device's Android Debug Bridge (ADB). That gives the malware a shell running as Android's shell user (UID 2000) — a context outside the app's own sandbox and permissions. From there, a one-click "deploy" button starts a Go-based payload maintained over a reverse tunnel.
This is a serious design boundary violation. Accessibility Services exist for assistive technology; using them to silently enable developer-mode debugging and auto-pair with ADB turns the platform's own diagnostic surface into a persistence and control channel. Defenders should treat any app requesting Accessibility that subsequently enables wireless debugging as inherently hostile.
Hourly rebuilds defeat hash-based AV
The console's ability to rebuild and re-sign the same malware on an hourly cadence — publishing to Amazon S3 or a customer-controlled web server — is a straightforward but effective anti-detection tactic. Static hash-based detection, the backbone of legacy mobile threat defenses, becomes meaningless when the artifact changes every 60 minutes. MDM and enterprise mobile security tools that rely primarily on file reputation rather than behavioral indicators will miss this.
Who is exposed
Shield53 Recommendations
- Block third-party APK installation at the MDM level for managed Android devices. Disable "Install unknown apps" for all non-essential sources.
- Restrict Accessibility Service grants by policy. Any non-assistive app requesting Accessibility should be denied and flagged for review.
- Disable wireless debugging on managed devices and alert on any attempt to enable Developer Mode or USB/wireless debugging post-enrollment.
- Move OTPs off SMS where possible — passkeys, app-based TOTP, or hardware tokens eliminate the SMS-exfiltration revenue model that RatHat relies on for both credential theft and AI triage input.
- Hunt for the ADB pattern: a non-system app process running as UID 2000, or any outbound connection from a Go binary spawned under the shell user context, is a high-fidelity signal.
- Behavior-based mobile defense over hash-based: the hourly rebuild tactic specifically targets file-reputation systems. Use EDR/MTD that monitors Accessibility misuse, ADB pairing events, and unexpected outbound tunnels.
- Monitor for consumer-genAI API egress from compromised endpoints. RatHat calling Gemini from inside a victim environment is a detectable pattern; many similar operations will reuse the same API endpoint families.
The takeaway isn't that AI is making malware smarter. It's that AI is making criminal operations more efficient — and the defenders who still treat mobile malware as a consumer-tier problem are the ones most likely to be on the wrong end of the triage.