据安全公司 Cleafy 称,RatHat 的运营者构建并发布安卓银行木马,并通过 Web 控制台控制受感染的手机。自 2026 年 4 月以来,Cleafy 已追踪到近 100 次该控制台的部署案例。该公司表示,这符合“恶意软件即服务”(malware-as-a-service)模式,其中每个客户运行一个独立的副本。
该控制台存储了恶意软件从每部手机收集的数据,包括短信以及输入到覆盖在银行应用上的虚假登录屏幕中的密码。
其最新版本要求谷歌的 Gemini AI 模型根据这些消息估算每位受害者的银行账户余额,并将手机分为高价值和中价值两组。
Cleafy 分析过的样本中没有任何内容使用该模型来转移资金。该公司表示,其作用是“决定哪些受害者值得运营者投入时间”。
一个控制台,三个版本
Cleafy 称,受害者手机上的恶意软件自 2025 年底以来变化不大,但其背后的控制台已被替换。
2025 年底和 2026 年 2 月的样本连接到一个名为 Fisher 的早期控制台。在 2026 年 4 月至 9 月期间,有三个新版本在使用,它们都基于相同的代码构建。
第一个版本自称“BlackCat Remote Control Management”。接下来的两个版本分别命名为 Panda Workshop V5 和 V6。
每个版本也是一个构建工具。通过控制台,运营者可以构建恶意软件,将其隐藏在看似无害的应用程序内部并进行签名。然后,控制台将完成的应用程序发布到 Amazon S3 或 Web 服务器,而无需运营者接触托管设置。
控制台还可以按计划重新构建应用程序,例如每小时一次。每次重新构建都会从相同的恶意软件创建新文件,Cleafy 表示这是为了针对通过哈希值识别已知文件的工具。
最新版本还添加了虚假下载页面的模板,包括一个名为 Google Store 的页面。
一键获取 Shell 访问权限
Zimperium 本月早些时候发现,RatHat 通过短信和指向第三方下载网站的在线广告接触手机。
安装后,该应用会请求无障碍(Accessibility)访问权限,允许应用读取屏幕并替用户点击。借助此权限,该应用启用无线调试,从屏幕上读取配对代码,并连接到手机的 Android Debug Bridge (ADB),这是安卓内置的调试工具。
这使得恶意软件获得了一个以安卓 shell 用户(UID 2000)运行的 shell,位于应用被授予的权限之外。
Cleafy 发现,通过控制台,运营者可以一键使用该 shell。一个部署按钮会启动一个单独的用 Go 语言编写的程序,该程序通过反向隧道保持可达,这是手机向运营者服务器打开的连接。
与 ADB 的配对是自动进行的,但 Go 程序仅在运营者点击部署后才运行。
该程序改变了运营者观看屏幕的方式。通过应用进行屏幕截图使用的是安卓的一项功能,它会要求受害者授权并在运行时显示录制图标。
相反,Go 程序使用名为 minicap 和 minitouch 的工具来流式传输屏幕并发送点击操作,无需权限提示且无录制图标。
这两个工具在安卓 14 及更高版本上均无法工作,使得这些手机只能使用应用自带的屏幕截图功能和权限提示。Cleafy 还描述了一种使用名为 screencap 的工具的备用方法,帧率约为每秒 5 帧,但未具体说明其覆盖哪些安卓版本。
在受害者移除应用后,Go 程序会继续运行,直到手机重启。Zimperium 发现,该程序还可以在应用被删除后重新安装它,并重新开启其无障碍访问权限。
两份报告均未提供完全清除恶意软件的步骤。
控制台的使用范围
Cleafy 通过搜索控制台的页面标题和 Web 代码发现了这些部署案例。该数字计算的是控制台部署次数,而非受感染的手机数量。
Cleafy 未说明什么算作一次部署,且其报告和 Zimperium 的报告均未提供具体的受害者人数。
控制台限制了操作员账户的数量,并对非管理员隐藏了部分功能模块。Cleafy 表示,这些限制仅在用户是开发者无法完全信任的客户时才有意义。
Cleafy 观察到的 IP 地址中,近一半位于一个注册于新加坡的网络 AS4907 上。
两端的 Gemini
Cleafy 发现,第一个控制台版本允许操作员从多个 AI 提供商中进行选择。当手机的 AI 评分超过设定阈值时,它还可以发送 Telegram 警报。
最新版本仅支持 Gemini,并引导操作员前往 Google AI Studio 获取密钥。
RatHat 在手机端也使用 Gemini。其内置的点击指令是针对特定手机制造商的界面、Android 版本和语言编写的,因此在作者未预料到的设备上会失效。
当出现这种情况时,恶意软件会将屏幕布局发送给 Gemini,并询问应在何处点击。它通过存储在自身设置中的 API 密钥直接从手机调用 Gemini。
Cleafy 表示,该功能仅用于保持无线调试设置的正常运行。
Android 恶意软件此前也曾这样做过。ESET 在二月描述的 PromptSpy 也会将屏幕布局发送给 Gemini,并遵循其点击指令。
指标与检测
Cleafy 列出了控制台命令与控制(C2)服务器、下载链接和恶意软件样本的这些指标:
域名:admin.chunhuating[.]best(Panda Workshop V6 的 C2,2026 年 9 月)
域名:admin.xiongmaocs[.]pics(Panda Workshop V5 的 C2,2026 年 8 月)
IP:8.231.120[.]246(BlackCat 的 C2,2026 年 4 月)
域名:admin.rathat[.]live(Fisher 的 C2,2025 年 12 月和 2026 年 2 月)
URL:hxxps://dramaspoolcoa[.]com/en.html(下载链接,2026 年 9 月)
URL:hxxps://rathat[.]me/app-release-rat-hat-live.apk(下载链接,2025 年 12 月和 2026 年 2 月)
MD5:116346cace7f00ba557034b534d40791(样本,2026 年 9 月)
MD5:8fdc21e25097a46528211274e54330e1(样本,2026 年 2 月)
MD5:f83357b2d47c7d38ee53943373961211(样本,2025 年 12 月)
控制台倾向于使用以 admin. 开头的网址,而最新版本的后台则使用 adminapi.,并采用 .best、.beer 和 .top 等廉价顶级域名。
一旦 Go 程序部署完成,minicap 和 minitouch 文件会以其实名存放在 /data/local/tmp 目录下,扫描工具可以在此找到它们。Cleafy 表示,安全工具应监控以 shell 用户 UID 2000 身份在手机上运行的进程。
所列地址之一 admin.xiongmaocs[.]pics 也出现在 Zimperium 在其早期分析中发布的指标列表中。
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.
The console stores what the malware collects from each phone, including text messages and passwords entered into fake login screens overlaid on banking apps.
Its latest version asks Google's Gemini AI model to estimate each victim's bank balance from those messages and sorts the phones into high-value and mid-value groups.
Nothing in the samples Cleafy analyzed uses the model to move money. Its role is "deciding which victims are worth an operator's time," the company said.
One Console, Three Versions
The malware on victims' phones has changed little since late 2025, Cleafy said. The console behind it has been replaced.
Samples from late 2025 and February 2026 connected to an earlier console named Fisher. Three new versions were in use between April and September 2026, all built from the same code.
The first calls itself BlackCat Remote Control Management. The next two are named Panda Workshop V5 and V6.
Every version is also a build tool. From the console, an operator can build the malware, hide it inside a harmless-looking app, and sign it. The console then publishes the finished app to Amazon S3 or to a web server, without the operator having to touch the hosting setup.
The console can also rebuild the app on a schedule, such as every hour. Each rebuild creates a new file from the same malware, which Cleafy said is aimed at security tools that spot known files by their hash.
The latest version also adds templates for fake download pages, including one called Google Store.
Shell Access in One Click
RatHat reaches phones through text messages and online ads that lead to third-party download sites, Zimperium found earlier this month .
Once installed, the app asks for Accessibility access, which lets an app read the screen and tap for the user. With it, the app enables wireless debugging, reads the pairing code from the screen, and connects to the phone's Android Debug Bridge (ADB), a debugging tool built into Android.
That gives the malware a shell that runs as Android's shell user (UID 2000), outside the permissions granted to the app.
From the console, the operator can use that shell with one click, Cleafy found. A deploy button starts a separate program written in Go that stays reachable through a reverse tunnel, a connection the phone opens to the operator's server.
Pairing with ADB happens automatically, but the Go program runs only after the operator clicks deploy.
That program changes how the operator can watch the screen. Screen capture through the app uses an Android feature that asks the victim for permission and shows a recording icon while it runs.
The Go program instead uses tools called minicap and minitouch to stream the screen and send taps, with no permission prompt and no recording icon.
Neither tool works on Android 14 and later, leaving those phones with the app's own screen capture and permission prompt. Cleafy also described a backup method using a tool called screencap at about 5 frames per second, but did not specify which Android versions it covers.
The Go program keeps running after the victim removes the app, until the phone restarts. Zimperium found that the program can also reinstall the app after it is deleted and turn its Accessibility access back on.
Neither report provides steps to remove the malware completely.
How Widely the Console Is Used
Cleafy found the deployments by searching for the console's page titles and web code. The figure counts console deployments, not infected phones.
Cleafy did not say what counts as one deployment, and neither its report nor Zimperium's gives several victims.
The console limits the number of operator accounts and hides some sections from non-admins. Cleafy said those limits only make sense if the users are customers the developers do not fully trust.
Nearly half of the IP addresses Cleafy observed are on one Singapore-registered network, AS4907.
Gemini on Both Ends
The first console version let operators pick from several AI providers, Cleafy found. It could also send a Telegram alert when a phone's AI score passed a set level.
The latest version works only with Gemini and directs operators to Google AI Studio to get a key.
RatHat also uses Gemini on the phone itself. Its built-in tap instructions are written for specific phone makers' interfaces, Android versions, and languages, so they fail on devices its authors did not anticipate.
When that happens, the malware sends the screen's layout to Gemini and asks where to tap. It calls Gemini straight from the phone, using an API key stored in its own settings.
Cleafy said the feature is used only to keep the wireless debugging setup working.
Android malware has done this before. PromptSpy , which ESET described in February, also sent Gemini the screen layout and followed its tap instructions.
Indicators and Detection
Cleafy listed these indicators for the consoles' command-and-control (C2) servers, download links, and malware samples:
Domain : admin.chunhuating[.]best (C2 for Panda Workshop V6, September 2026)
Domain : admin.xiongmaocs[.]pics (C2 for Panda Workshop V5, August 2026)
IP : 8.231.120[.]246 (C2 for BlackCat, April 2026)
Domain : admin.rathat[.]live (C2 for Fisher, December 2025 and February 2026)
URL : hxxps://dramaspoolcoa[.]com/en.html (download link, September 2026)
URL : hxxps://rathat[.]me/app-release-rat-hat-live.apk (download link, December 2025 and February 2026)
MD5 : 116346cace7f00ba557034b534d40791 (sample, September 2026)
MD5 : 8fdc21e25097a46528211274e54330e1 (sample, February 2026)
MD5 : f83357b2d47c7d38ee53943373961211 (sample, December 2025)
The consoles tend to use web addresses that start with admin., plus adminapi. for the latest version's back end, on cheap top-level domains such as .best, .beer, and .top.
Once the Go program is deployed, the minicap and minitouch files sit in /data/local/tmp under their real names, where a scan can find them. Cleafy said security tools should watch what runs on phones as the shell user, UID 2000.
One of the listed addresses, admin.xiongmaocs[.]pics, also appears in the indicator list Zimperium released with its earlier analysis.
首次收录 · 2026-09-29 · 9.73 分