Researchers at Cleafy have documented how the operators of RATHat, an Android banking trojan, left the malware almost unchanged from late 2025 to September 2026.
They replaced its command-and-control (C2) panel three times in six months. The panel started as “BlackCat” and became “Panda Workshop.” It now builds, signs, and publishes malware with no hands-on work from the operator.
RATHat spreads through malvertising and smishing, targeting victims in Europe, LATAM, and South-Eastern Asia. Once a victim grants the Accessibility Service, the app enables wireless debugging, reads the pairing code off the screen, and pairs with the device’s ADB daemon.
RATHat Android Trojan’s Panda Workshop C2 Panel
That gives it a shell, which it uses to stage a native Go service and an FRP client that opens a reverse tunnel to the operator.

The Go service runs as UID 2000 (the shell user), outside the app’s permission model. It survives removal of the malicious app until the device reboots.
The same design appeared in a late-2025 crypto-trading-bot decoy and a February 2026 “StripChat” campaign. Only the infrastructure behind it changed.
Researchers recovered three generations, all in Simplified Chinese and all live between April and September 2026:
- BlackCat (黑猫远控管理): The first release, with no version number. It established the sections later versions inherited: device management, credential harvesting, injections, builders, remote control, and AI integration.
- Panda Workshop V5: Renamed the whole REST API, added operator two-factor authentication (TOTP) and a floating AI widget that scores a victim’s bank balance.
- Panda Workshop V6: Obfuscated the entire frontend, added a phishing download-page builder, and consolidated its AI features on Gemini.
Two artifacts tie the generations together. Frontend chunks are SHA256-identical between BlackCat and V5, and V6 still stores navigation state under a “fisher_current_page” key, a leftover from the earlier “Fisher” panel.
The panel handles the whole APK lifecycle. Operators set server URLs and a decoy page, toggle permissions, and pack the payload into a dropper. An automatic build option can regenerate the payload as often as every hour, which defeats hash-based detection while the implant stays the same.

Publishing works through AWS S3 with CloudFront or through BaoTa, a hosting control panel popular with Chinese-speaking providers. V6 adds templated landing pages, including a fake “Google Store” layout.
Some controls serve the developers, not the criminals using the panel. These include a cap on concurrent users (/api/license/max-users) and role-gated sections for admins. They add nothing against victims. They make sense only if the users are customers the developers don’t fully trust.
Pivoting on panel titles and frontend artifacts revealed nearly 100 separate deployments since April 2026. Nearly half of the observed IPv4 addresses sit on AS4907 (BGPNET, Singapore). Domains follow a pattern, with “admin.” for the frontend and, in V6, “adminapi.” for the backend, spread across cheap TLDs such as .best, .beer and .top.
The operator triggers the Go service from a “one-click deployment” group. “Deploy service” sends DEPLOY_LOCAL_SERVICE, and “full deployment” sends FULL_DEPLOY, which retries pairing first. The binary lands in /data/local/tmp and opens a local HTTP server on port 7912.
Screen capture can use minicap, fetched from the C2, which shows no consent dialog or recording indicator. The standard route, MediaProjection, requires user approval. The shell route has limits. Neither tool works on Android 14 and above. The binaries also keep unobfuscated filenames, so a scan of /data/local/tmp exposes them.
On the device, the malware sends the live accessibility tree to a Gemini flash model when its static automation fails on an unfamiliar phone. The model returns tap coordinates. The API key sits in the malware’s configuration, with temperature fixed at 0.1 and output capped at 256 tokens.
On the panel side, an LLM reads collected SMS messages, estimates bank balances, and ranks devices as high-value or mid-value. BlackCat could also send Telegram alerts when a device’s score passed a threshold. The AI isn’t committing fraud. It is choosing which victims deserve an operator’s time.
Nothing in the analyzed samples performs an automated transfer. Still, an LLM that reads the interface and returns the next action could bring back automated transfer systems (ATS) without the per-bank scripting that made them costly.
Defenders should monitor what executes under UID 2000, flag unexpected wireless-debugging activity, and look for binaries in /data/local/tmp.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.