RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects from each phone,
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/rathat-android-malware-console-uses.html
![]()

