MediumNewsLLM-specific
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
- Published
- Record updated
Summary
Cleafy reports that RatHat's operators run an Android banking trojan through a web console, with nearly 100 deployments traced since April 2026. The latest console version asks Google's Gemini model to estimate each victim's bank balance from intercepted text messages and sorts phones into high-value and mid-value groups. Cleafy found no samples using the model to move money.
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoGoogle is launching a one-stop Gemini agent for your work tasksSame vendor · The Verge (AI)
- InfoThe Pentagon Hopes to Speed Up ‘Kill Chain’ AI Buys With 5-Minute VideosSame vendor · Wired (Security)
- InfoAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessSame vendor · SecurityWeek
- LowFake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA CodesSame vendor · The Hacker News