Monday, September 28, 2026
NewsezeNews with Rewards · Earn while you read
+5 credits / query
cyber

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Newseze Wire·Mon, Sep 28, 5:38 PMWire: The Hacker News
Open original source Read full story (in-site)
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026.

Sourcing & attribution. Newseze provides AI-curated summaries, narrative framing, and editorial analysis. The underlying reporting was contributed by The Hacker News; tap “Open original source” above to read their full reporting and support the contributing newsroom directly.

Newseze Analysis96 words · original commentary · full read loading…
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. The story falls into Newseze's cyber desk and is being actively tracked by our editorial team. Calm framing, primary-source references, and respectful tone — every Newseze story is scored for drama and conspiracy before it reaches you. Worth knowing: Newseze refreshes its newsroom every hour and flags fast-moving local and breaking news as it develops. Watch this page for updates. Reporting: The Hacker News.
Ask Us · Any Story, Any AnswerBe the first to ask

Newseze's algorithm reads the story and answers your question — calmly, factually, with source attribution. No comments, no flame wars — just answers.

No questions yet. Be the first.

Answers reflect Newseze's editorial framework applied under fair use (17 U.S.C. § 107). Not financial, legal, medical, or tax advice. Hate speech and racial slurs are blocked.

Related stories

Google Alerts Enterprise to Mass Exploitation of Oracle PeopleSoft Flaw; WAF Bypasses Enabling Remote Code Execution
CYBERtrust 90
Google Alerts Enterprise to Mass Exploitation of Oracle PeopleSoft Flaw; WAF Bypasses Enabling Remote Code Execution

Why it mattersA critical vulnerability in widely-used enterprise software is being actively exploited at scale across sectors, putting organizations at immediate risk of unauthorized access and data breach unless they patch or deploy …

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.…

ChellaBy Chella·2d ago
WireThe Hacker News
Full Analysis Comment PostRead →
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
CYBERTrending Righttrust 80
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Why it mattersAuthorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In…

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the lon…

ChellaBy Chella·Aug 27
WireKrebs on Security
Full Analysis Comment PostRead →
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
CYBERtrust 80
Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

Why it mattersAI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to hum…

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across bus…

ChellaBy Chella·8h ago
WireThe Hacker News
Full Analysis Comment PostRead →