From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Indicators of Compromise
- domain: admin.chunhuating.best
- domain: admin.xiongmaocs.pics
- domain: admin.rathat.live
- url: https://dramaspoolcoa.com/en.html
- url: https://rathat.me/app-release-rat-hat-live.apk
- hash: 116346cace7f00ba557034b534d40791
- hash: 8fdc21e25097a46528211274e54330e1
- hash: f83357b2d47c7d38ee53943373961211
From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat
Description
RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native Go service that operates outside Android's permission model. The operation's primary investment lies in its infrastructure, with three successive Command-and-Control panel generations emerging between April and September 2026: BlackCat, followed by Panda Workshop V5 and V6. These panels function as complete malware factories, building, signing, and publishing samples automatically while implementing scheduled rebuilds to evade hash-based detection. Nearly 100 separate deployments across Europe, LATAM, and South-Eastern Asia suggest a Malware-as-a-Service model. Notably, the operation integrates AI on both sides: the malware uses Gemini models to locate on-screen controls when automation fails, while the panel employs LLMs to estim...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat"]
- Pulse Id
- 6abaccf85f7a199ca2ad50c6
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainadmin.chunhuating.best | — | |
domainadmin.xiongmaocs.pics | — | |
domainadmin.rathat.live | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://dramaspoolcoa.com/en.html | — | |
urlhttps://rathat.me/app-release-rat-hat-live.apk | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash116346cace7f00ba557034b534d40791 | — | |
hash8fdc21e25097a46528211274e54330e1 | — | |
hashf83357b2d47c7d38ee53943373961211 | — |
Threat ID: 6abc0536680226ef681ded05
Added to database: 09/29/2026, 18:36:38 UTC
Last updated: 09/29/2026, 18:36:38 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.