$ techbeacon▋
Darkweb

AI‑Powered Android Trojan RATHat Leverages Google Gemini to Automate On‑Device Banking Attacks

AI‑Powered Android Trojan RATHat Leverages Google Gemini to Automate On‑Device Banking Attacks

A new Android banking trojan, dubbed RATHat, has been documented to harness Google's Gemini generative AI models, enabling the malware to autonomously navigate unfamiliar mobile interfaces and conduct on‑device financial fraud.

Security researchers at GBHackers uncovered the malware in early 2024. RATHat installs a hidden component on compromised devices that calls Gemini to interpret screen layouts, locate input fields and simulate user actions such as entering credentials or authorizing transfers. By delegating these tasks to an AI model, the trojan can adapt to a wide range of banking apps without the need for hard‑coded scripts.

The malware also includes a remote operator panel that employs AI to evaluate the value of potential targets. By analysing transaction histories, account balances and user behavior, the panel flags high‑value victims and prioritises them for immediate exploitation. This dual‑AI approach—on‑device navigation and backend target scoring—marks a significant escalation in the sophistication of mobile banking threats.

While AI‑enhanced malware is not entirely new, RATHat is among the first to integrate a large‑language model directly into the attack chain on a consumer device. Earlier examples have used AI for code obfuscation or phishing email generation, but the on‑device use of Gemini to interact with graphical user interfaces represents a novel operational capability that could lower the barrier for less‑skilled threat actors.

The emergence of RATHat raises concerns for banks and mobile users alike. Traditional security solutions that rely on signature‑based detection may struggle to keep pace with malware that can modify its behaviour in real time based on AI‑driven observations. Users could see unauthorized transfers or credential theft even when they believe they are using trusted banking apps.

Cyber‑security firms are urging immediate mitigation steps: keep devices updated, install apps only from official stores, enable two‑factor authentication, and consider mobile security suites that monitor anomalous UI interactions. Google has not yet commented publicly on the misuse of Gemini, but the company has previously warned about the potential for its models to be weaponised and is expected to review its API access policies.

Analysts predict that AI‑driven malware like RATHat will become more common as generative models become easier to integrate and cheaper to run. Detecting such threats may require behavioural analytics that can spot AI‑generated UI actions, as well as tighter controls on how third‑party apps can invoke large‑language models on Android devices.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related