Daily Tech Now

Tech News on AI, Smartphones & Gadgets

RATHat Banking Trojan Uses Google Gemini for Android Attacks

RATHat Banking Trojan Leverages Google Gemini The insidious RATHat banking trojan now actively employs Google Gemini as an intelligent assistant to infect smartphones. According to dedicated researchers at Cleafy, this neural network helps the malware navigate unfamiliar Android interfaces. Furthermore, it assists the malicious operators in identifying more lucrative victims. Deceptive Initial Infection As cybersecurity…

RATHat banking trojan utilizing Google Gemini AI on an Android smartphone

RATHat Banking Trojan Leverages Google Gemini

The insidious RATHat banking trojan now actively employs Google Gemini as an intelligent assistant to infect smartphones. According to dedicated researchers at Cleafy, this neural network helps the malware navigate unfamiliar Android interfaces. Furthermore, it assists the malicious operators in identifying more lucrative victims.

Deceptive Initial Infection

As cybersecurity specialists report, the elaborate scheme always begins with clever deception. The malware meticulously masquerades as a legitimate application and persuasively urges users to enable Accessibility services. Once granted this critical access, the trojan autonomously activates wireless debugging. Subsequently, it covertly connects to the compromised device via the Android Debug Bridge (ADB).

Following this connection, the remote operator can deploy a separate Go-based service possessing elevated system user privileges. At this stage, a highly unpleasant reality emerges: simply deleting the deceptive application is utterly insufficient. The hidden service operates entirely independently and can stubbornly remain active until a complete system reboot. Shockingly, it even possesses the capability to reinstall the deleted APK.

AI-Powered Interface Navigation

Google Gemini provides crucial assistance, helping RATHat effortlessly bypass the frustrating differences between various Android versions. It also smoothly overcomes obstacles presented by different regional languages and distinct manufacturer overlays. When the trojan’s standard automated clicking script falters, it intelligently transmits the interface structure directly to the AI model. It then politely requests guidance on locating the necessary buttons. This sophisticated approach requires significantly less manual configuration and dramatically expands the potential for automated infections.

Targeting Lucrative Victims

On the perpetrators’ side, the artificial intelligence meticulously analyzes intercepted SMS messages. It accurately evaluates banking balances and strategically helps sort compromised devices based on their overall financial attractiveness. Since April, Cleafy has identified nearly 100 distinct deployments of this sophisticated command infrastructure. Following a deep dive into the evolving C2 panel behind RATHat, researchers strongly suspect the operation functions under a highly organized “malware-as-a-service” model.

About the Author

Trang Nguyen Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *