Skip to content

RatHat Android Malware: How to Protect Your Phone from a Banking Trojan

Nifty Tech Finds
10 min read
14 views

RatHat is an Android banking trojan that security firm Cleafy detailed on September 28, 2026 — and it’s one of the first pieces of malware caught using a live AI model, Google’s Gemini, to find its way around unfamiliar banking apps. It spreads through fake apps, text-message links, and shady download sites, then tricks you into granting it the one permission it needs to take over your screen. Here’s exactly how it works, and the specific steps that keep it off your phone.

Key Takeaways

  • RatHat is an Android banking trojan documented by security firm Cleafy on September 28, 2026. It spreads via smishing texts, malicious ads, fake download pages, and sideloaded apps — never through a legitimate Google Play Store listing.
  • It abuses Android’s Accessibility Service to see your screen and tap on your behalf, then quietly enables Developer Options and Wireless Debugging to gain deeper, harder-to-remove access.
  • RatHat is notable for sending screenshots of its target’s screen to Google’s Gemini AI, asking it where to tap when the malware’s scripted automation gets confused by an unfamiliar app layout.
  • It steals login credentials, PINs, and intercepted SMS one-time codes. Cleafy has tracked nearly 100 separate campaigns since April 2026 across Europe, Latin America, and Southeast Asia.
  • You can avoid it almost entirely by never sideloading apps and never granting Accessibility permissions to an app that doesn’t clearly need them — and there are concrete steps to take if you think you’re already infected.

What Is RatHat?

RatHat is a type of malware called a banking trojan — malicious software disguised as something harmless that, once installed, specifically targets your financial accounts. Cleafy’s research traces RatHat’s command-and-control infrastructure (the servers criminals use to control infected phones) back to late 2025, with its first widespread campaigns starting in April 2026. The operators have rebranded their control panel twice since then, most recently to something called “Panda Workshop,” and Cleafy says nearly half of the IP addresses behind it trace to a single network based in Singapore.

What makes RatHat stand out from older banking trojans isn’t really the malware on your phone — it’s the operator tooling behind it. The control panel can build, digitally sign, and publish new versions of the malicious app on a schedule, which helps it dodge security scanners that look for known, unchanging files. Cleafy’s researchers describe the overall operation as consistent with a malware-as-a-service model, meaning the people who built RatHat appear to be renting it out to other criminals rather than running every scam themselves.

How RatHat Gets Onto Your Phone

RatHat doesn’t exploit some secret flaw in Android — it relies on you installing it yourself. Cleafy’s report lists several ways it reaches victims: smishing (phishing text messages with a malicious link), malicious ads, fake download portals that imitate real app stores, and listings on third-party app forums. In every case, the app disguises itself as something legitimate — a delivery tracker, a utility app, a cleaner tool — and then uses social engineering to talk you into enabling Accessibility Service, a legitimate Android feature originally built to help people with disabilities use their phones, which also happens to let an app see everything on your screen and perform taps and swipes for you.

Once Accessibility is granted, the app doesn’t need you to tap anything else. It automatically turns on Developer Options and Wireless Debugging — settings normally reserved for app developers testing their own software — and uses them to pair with the phone’s own debugging interface. That gives it shell-level system access, a much deeper level of control than a normal app ever gets, which it uses to plant a hidden background service that can survive even if you delete the visible app, persisting until the phone is rebooted or that hidden component is specifically removed.

How RatHat Uses AI to Steal From You

Most banking trojans script their actions in advance: tap this exact pixel, wait, tap that one. The problem for criminals is that this breaks constantly — a different phone brand, a different language setting, or a banking app update can all throw the script off. Cleafy’s analysis found that RatHat gets around this by converting what’s currently on the victim’s screen into a structured description and sending it to Gemini Flash, one of Google’s AI models, along with a question like “where is the login button” or “what should I tap next.” Gemini sends back coordinates or instructions, and the malware acts on them.

Cleafy is careful to note that Gemini itself isn’t committing fraud — it’s being used the way a developer might use any AI coding assistant, to make brittle automation more reliable across different devices and apps. But that distinction matters less to a victim than the practical effect: AI assistance makes this kind of malware more adaptable, and likely more durable, than older banking trojans that broke the moment their target app changed its layout. It’s part of a broader pattern we’ve covered before, where AI agents end up helping automate attacks in ways their designers didn’t originally plan for.

What RatHat Actually Steals

Once it’s in control, RatHat captures login credentials and PINs as you type them, and intercepts the one-time SMS codes banks send for two-factor authentication — meaning 2FA delivered by text message doesn’t fully protect you if this malware is already running on the same device receiving those texts. According to Cleafy, the criminal control panel then uses AI to sort through intercepted messages, estimate how much money is in each victim’s account, and rank victims into “high-value” and “mid-value” tiers — effectively letting operators prioritize who to target next. Cleafy says it hasn’t observed RatHat actually completing an automated money transfer yet, but warned the same AI-assisted approach could eventually be extended that far.

How to Protect Your Phone From RatHat and Similar Malware

Before You’re Infected

  • Don’t sideload apps. Install from the Google Play Store only. Sideloading — installing an app file directly instead of through an official store — skips the malware scanning Google applies to Play Store listings.
  • Treat unexpected texts with links as hostile. A bank, delivery company, or government agency texting you a link to “verify” something or “track” a package is a classic smishing setup. Go to the real app or website directly instead of tapping the link.
  • Be suspicious of any app that asks for Accessibility permission. A flashlight app, a photo editor, or a cleaner tool has no legitimate reason to need it. If an app you just installed asks to “turn on Accessibility” to function, that’s a major red flag — close it and uninstall.
  • Keep Google Play Protect turned on (Settings → Security → Google Play Protect) and let it scan apps automatically, including ones installed outside the Play Store.
  • Turn off Developer Options and USB/Wireless debugging unless you’re actually developing apps. Under Settings → System → Developer Options, you can disable the whole menu if you don’t use it, removing one of RatHat’s key escalation paths.

If You Think You’re Already Infected

Watch for warning signs: Accessibility Service turning on for an app you don’t remember approving, Developer Options appearing when you never enabled it, unusual battery drain, apps you don’t recognize, or an unexpected alert from your bank about a login or transaction you didn’t make.

  1. Disconnect from the internet first. Turn on airplane mode or disable Wi-Fi and mobile data so the malware can’t send out any more of your data or receive new instructions.
  2. Boot into Safe Mode (press and hold the power button, then long-press “Power off” on most Android phones) and uninstall any app you don’t recognize or that you installed outside the Play Store recently.
  3. Run a Google Play Protect scan once you’re back in normal mode, and consider a scan from a reputable mobile security app as a second opinion.
  4. Change your banking passwords and PINs from a different, trusted device — not the phone you suspect is infected — and contact your bank to flag possible fraud and review recent activity.
  5. Switch two-factor authentication away from SMS where your bank allows it, to an authenticator app or a physical security key, since intercepted text codes are exactly what this malware is built to grab.
  6. When in doubt, back up your photos and files, then factory reset the phone. Because RatHat can plant a background component with shell-level access that survives app removal, a full factory reset and reboot is the only way to be certain nothing is left running.

Why This Matters Beyond RatHat

RatHat is one entry in a much bigger trend: criminals plugging AI models into old attack techniques to make them more resilient. We’ve seen the same dynamic play out on the desktop side, where AI agents helped a threat actor breach 395 organizations by automating steps that used to require a human attacker at the keyboard, and in security researchers’ warnings about agentic AI browsers acting on a user’s behalf in ways that can be hijacked. The common thread is the same: AI doesn’t need to be malicious on its own to make malicious software more effective. The practical defense also stays the same across all of these cases — be deliberate about which permissions you hand over, and treat “just grant this one permission” requests from unfamiliar apps as the red flag they are.

Frequently Asked Questions

What is RatHat Android malware?

RatHat is an Android banking trojan documented by security firm Cleafy on September 28, 2026. It tricks victims into granting Accessibility Service permissions, then uses that access to steal login credentials, PINs, and SMS-based two-factor codes. It is notable for using Google’s Gemini AI to help its automation adapt to different phones and banking apps.

How do I know if my phone is infected with RatHat?

Warning signs include Accessibility Service turning on for an app you don’t remember approving, Developer Options or Wireless Debugging appearing unexpectedly, unusual battery drain, unfamiliar apps, and unexpected bank alerts about logins or transactions you didn’t make.

Can RatHat steal my bank account even with 2FA enabled?

If your two-factor authentication relies on SMS codes, yes — RatHat specifically intercepts text messages on the infected device, including one-time codes. Switching to an authenticator app or a physical security key for 2FA removes this specific weakness, since those codes never arrive as an interceptable text message.

How do I remove Android banking malware like RatHat?

Disconnect from Wi-Fi and mobile data, boot into Safe Mode and uninstall unfamiliar apps, then run a Google Play Protect scan. Because RatHat can plant a hidden component with deep system access that survives app removal, a full factory reset is the most reliable way to be certain it is gone, followed by changing your banking passwords from a separate device.

Is my phone safe if I only download apps from the Google Play Store?

Staying inside the Play Store removes the main way RatHat and similar trojans spread, since Google scans Play Store listings for known malware. It is not a 100% guarantee against every threat, but avoiding sideloaded APKs, fake download sites, and links from text messages closes off the specific infection paths Cleafy documented for RatHat.

Sources: Cleafy, Infosecurity Magazine, GBHackers.

Leave a Comment

Monthly digest

Get the month in AI, once a month

One email a month with everything worth reading from NiftyTechFinds. No spam, no daily pings, unsubscribe in one click.

LET’S KEEP IN TOUCH!

We’d love to keep you updated with our latest news and offers 😎

We don’t spam! Read our privacy policy for more info.