RatHat Android Banking Trojan Uses AI to Identify Valuable Victims

Security researchers have analysed RatHat, an Android banking trojan that uses a web-based control panel to manage infected devices. According to Cleafy, newer versions reportedly use Google's Gemini API to assess intercepted messages and estimate which victims may have higher-value bank accounts.

RatHat is spread through SMS messages and online advertisements that direct users to third-party app stores. After installation, the malware requests Android Accessibility permission and can enable wireless debugging. On older Android versions, attackers can use screen capture and touch-control capabilities to monitor and interact with the device.

The threat is particularly relevant to smartphone users who rely on their devices for UPI, mobile banking and OTPs. Malware capable of reading messages and controlling a screen could expose banking alerts or authentication codes and potentially allow attackers to perform actions on the device.

The reported delivery methods are also familiar to Indian users. Fake KYC updates, bank alerts and APK links shared through SMS or messaging platforms can trick people into installing malicious applications. Personal smartphones used for work can create an additional risk for businesses if corporate accounts or authentication apps are accessible from an infected device.

Fake Claude Code Installer Spreads Fileless .NET Infostealer via SEO PoisoningFake Claude Code Installer Spreads Fileless .NET Infostealer via SEO Poisoning

Threats such as RatHat highlight the importance of layered protection for mobile users and online payments. Net Protector Total Security Fraud Protector can help strengthen protection for identity, passwords, email and online payments, while businesses can use Net Protector Mobile Device Management to manage company devices and reduce risks from unauthorised applications.