Cleafy's analysis of the RatHat Android banking trojan found that the implant itself changed little between late 2025 and September 2026 while its command-and-control panel went through three generations in six months and rebranded from BlackCat to Panda Workshop, with nearly 100 separate deployments observed since April 2026 — a pattern consistent with a malware-as-a-service operation rather than a single actor. The panels can build, sign and publish new Android samples directly from the operator console and can regenerate samples on a schedule, producing fresh files to defeat hash-based detection while the underlying implant stays largely unchanged. Panda Workshop V5 added two-factor authentication for operators, and V6 added a phishing download-page builder; the panels also use AI to rank potential victims by value. Cleafy points to account limits and role-based access as further evidence of a commercial model in which customers buy a defined capacity. The significance for financial institutions is that the barrier to running an Android banking-trojan campaign has moved from development capability to a subscription, so the differentiator on the defensive side is detection and device-integrity telemetry rather than awareness of any single sample.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-30 |
| Source | Infosecurity Magazine |
| Reliability | Tier 3 |