Researchers at Cleafy identified nearly 100 deployments of the RatHat Android banking trojan between April and September 2026, finding a rapidly evolving malware-as-a-service platform behind an implant that has otherwise changed little since late 2025. Its command-and-control panels progressed from Fisher to BlackCat Remote Control Management and Panda Workshop V5/V6, enabling operators to build, sign, host, regenerate, and administer malicious Android applications. Victims are lured through SMS messages and online advertisements to third-party download sites.
RatHat abuses Android Accessibility services to activate wireless ADB debugging and gain a UID 2000 shell, allowing remote screen monitoring and input control. Operators can deploy a native Go component that persists after the malicious app is removed, retaining shell-level access until the device restarts. Panda Workshop V6 uses Google Gemini to estimate and rank victims by bank balance using harvested SMS data, while the implant can invoke an LLM to identify where to tap in unfamiliar device interfaces when conventional automation fails.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Cleafy published research documenting nearly 100 RatHat console deployments since April 2026 and an evolution from Fisher to BlackCat and Panda Workshop panels. The research described MaaS-style customer-operated consoles, Gemini-assisted victim ranking and navigation, and wireless-debugging abuse that can deploy a persistent Go service with shell-level control.
Cleafy identified admin.chunhuating[.]best as a Panda Workshop V6 C2 domain. The V6 panel included fraudulent download-page templates and used Google Gemini to assess harvested SMS data for estimated victim bank balances and prioritization.
Cleafy identified admin.xiongmaocs[.]pics as a Panda Workshop V5 C2 domain. This panel generation added two-factor authentication for C2 operators.
Cleafy identified 8.231.120[.]246 as a BlackCat control-server address in April 2026. RatHat console deployments began appearing from April onward, marking the shift away from the earlier Fisher infrastructure.
RatHat samples from late 2025 and February 2026 communicated with the earlier Fisher console. Cleafy identified admin.rathat[.]live as a Fisher C2 domain used in December 2025 and February 2026.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcethehackernews.com
Open sourcecleafy.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.