Skip to main content

From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat

0
Medium
Published: 09/28/2026 (09/28/2026, 20:24:24 UTC)
Source: AlienVault OTX General

Description

RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat"]
Pulse Id
6abaccf85f7a199ca2ad50c6

Indicators of Compromise

Domain

ValueDescriptionCopy
domainadmin.chunhuating.best
—
domainadmin.xiongmaocs.pics
—
domainadmin.rathat.live
—

Url

ValueDescriptionCopy
urlhttps://dramaspoolcoa.com/en.html
—
urlhttps://rathat.me/app-release-rat-hat-live.apk
—

Hash

ValueDescriptionCopy
hash116346cace7f00ba557034b534d40791
—
hash8fdc21e25097a46528211274e54330e1
—
hashf83357b2d47c7d38ee53943373961211
—

Threat ID: 6abc0536680226ef681ded05

Added to database: 09/29/2026, 18:36:38 UTC

Last updated: 09/29/2026, 18:36:38 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses