A newly identified Android malware family, tracked as RATHat, has been found calling on Google's Gemini AI models mid-attack to keep its remote-control chain working when infected devices don't behave as expected. Analysts have linked close to 100 separate deployments to the operation since April 2026, describing it as a fast-moving malware-as-a-service (MaaS) offering rather than the output of a single group.
What happened
RATHat abuses Android's Accessibility service to silently open Developer Options, enable wireless debugging, and read the on-screen pairing code needed to connect to the device's own Android Debug Bridge (ADB) interface — effectively pairing with itself under the built-in "shell" identity (UID 2000), a privilege level well above what a normal app can reach.
That pairing sequence depends on locating specific buttons and labels, which can shift across manufacturers, Android versions, and languages. When the malware's hard-coded matching fails, it packages a description of the current screen and sends it to Gemini Flash models directly from the infected device, using an API key embedded in its own configuration. Gemini returns tap coordinates or a resolved label, letting the malware complete the pairing step it would otherwise fail on. It's a narrower, more targeted use of AI than the fully adaptive on-device navigation seen in some other Gemini-assisted Android spyware — here, the model is called in specifically to rescue one fragile step.
Once ADB pairing succeeds, operators can push a lightweight companion service to the device with a single click. It runs independently of the visible app, opens a local HTTP server, and stays reachable through a reverse tunnel back to attacker infrastructure. Using standard Android testing utilities rather than the OS's screen-recording APIs, it can read screen content and inject touch input without triggering the recording indicator or permission prompt users would normally see — letting an operator drive the device largely unnoticed.
Behind the malware, the criminal control panel has evolved from an earlier build into newer versions that package an AI-driven balance-scoring feature, ready-made phishing page templates, and one-click build/sign/publish tooling — letting affiliates rebuild and repackage the app frequently to dodge hash-based detection while the underlying malicious code stays the same. A separate AI function reads intercepted SMS messages to estimate a victim's account balance and prioritize higher-value targets for the operator — reconnaissance, not the fraud step itself; researchers found no case of AI directly completing a fraudulent transfer.
Why it matters
This isn't AI carrying out an attack end-to-end — it's AI patched into one brittle part of an existing attack chain to make it more reliable across the huge variety of real-world Android devices. That's a meaningful shift: it lowers the custom-engineering effort needed to keep a mobile banking trojan working everywhere, and it's already showing up as a resale product rather than a one-off tool. Because the abused capability (wireless debugging pairing) is a legitimate developer feature and the companion service runs outside the visible app, uninstalling the app alone does not stop it — the background service persists until the device is rebooted.
What to do
- Treat any unsolicited request to enable Developer Options or wireless (ADB) debugging as a red flag, especially when triggered by an app rather than the user.
- On managed fleets, monitor and alert on activity from UID 2000 / the shell identity, and flag processes binding to unexpected local ports or opening reverse tunnels.
- Don't rely on file-hash detection alone — this operation rebuilds and re-signs its APK regularly specifically to defeat it; prioritize behavioral detection of Accessibility-service abuse and ADB self-pairing patterns.
- If compromise is suspected, check
/data/local/tmpand similar temp directories for known Android testing binaries (e.g.minicap,minitouch,screencap) deployed outside a legitimate testing context, and reboot the device — don't assume uninstalling the app alone clears the infection. - Educate users that no legitimate banking or financial app will ever ask them to enable Developer Options or debugging.
