GMAsia
    AI News·28 Sept 2026·via The Hacker News

    RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

    RatHat Android malware operators are using Google's Gemini AI to identify high-value victims. Security firm Cleafy reports nearly 100 deployments of the RatHat web console since April 2026. This malware-as-a-service model allows each customer to run a separate copy. The console stores data collected from infected phones, enabling targeted attacks.

    Nexa's Summary

    The use of Gemini by RatHat malware operators for victim identification shifts the threat landscape. This represents AI-powered targeting. The malware-as-a-service model, with 100 console deployments since April 2026, makes advanced tools accessible. This lowers the barrier for sophisticated attacks on Android users.

    For Asia, this means increased risk for financial institutions and their customers. Southeast Asian markets, with high Android penetration, are particularly vulnerable. Banks in Indonesia and Vietnam must enhance fraud detection and customer education. The ease of deploying such AI-enhanced malware could overwhelm existing defenses.

    The thing to watch is how quickly other threat actors adopt similar AI models. If more malware services integrate advanced AI for targeting, the cost of defense will rise. Regulators in Singapore and Hong Kong should consider new guidelines for AI-driven fraud prevention. The test for regional cybersecurity firms is to develop countermeasures that match this pace of AI adoption.

    Share this article

    Original reporting by The Hacker NewsWe don't republish, read the full story →

    Related reading

    6 stories