Skip to content
AI SecurityLLMllm-securityAgentic AI

RatHat banking trojan uses Google Gemini to generate overlay screens on infected devices

3 min read
Share

What RatHat does differently

Most Android banking trojans ship with pre-built overlay screens that imitate specific banking apps. Security researchers and financial institutions fingerprint these overlays and push detection updates. RatHat, documented by Unit 42 researchers, carries no overlay assets at runtime. Instead, it calls the on-device Gemini API with a prompt describing the layout of the targeted app's login screen and receives HTML and CSS back, which it renders as a WebView overlay. Each generated overlay is structurally distinct from any previously observed sample.

Why this bypasses existing defenses

Static overlay detection depends on file hashes, visual similarity matching against known templates, or the presence of embedded overlay assets inside the APK. RatHat carries none of these artifacts. The generated overlays are valid HTML produced by a language model, visually convincing, and different on every device. Signatures and hash-based detections will not catch the overlay itself. Detection must shift to behavioral signals: an app requesting Gemini API access alongside accessibility service permissions and SMS read access is a high-confidence indicator of overlay fraud tooling regardless of what the overlay content looks like.

The Gemini API and on-device AI abuse

Google's Gemini on-device API was designed for productivity and app-integration use cases. The API does not enforce restrictions on what kind of content it will generate, which means it can be invoked by malicious apps to produce phishing overlays, adaptive scripts, or social engineering text. This is not a vulnerability in Gemini itself. It is a predictable consequence of deploying capable language model APIs in an environment where arbitrary third-party apps have access to them. App store review processes do not operate at a speed that reliably intercepts this class of abuse before infections reach devices.

Recommended controls

For enterprise Android fleets managed through mobile device management, restrict API key provisioning to allowlisted applications and enforce Play Protect verification. For security teams building Android malware detection profiles, add Gemini API invocation alongside accessibility service activation to your behavioral indicator set. Banking institutions should evaluate whether their overlay detection systems rely solely on asset matching and, if so, prioritize adding behavioral signals. Users should install applications only from the Play Store, deny accessibility service requests from apps that have no documented need for those features, and treat any app requesting both SMS and Gemini API permissions as high risk.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are building behavioral detection coverage for AI-assisted mobile malware.

Related articles