Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-30 · updated: 2026-09-30 · tags: [incident, financial-services, android, phishing] · confidence: high · severity: low · affected_sectors: [financial-services] · au_impact: true

Cleafy's analysis of the RatHat Android banking trojan found that the implant itself changed little between late 2025 and September 2026 while its command-and-control panel went through three generations in six months and rebranded from BlackCat to Panda Workshop, with nearly 100 separate deployments observed since April 2026 — a pattern consistent with a malware-as-a-service operation rather than a single actor. The panels can build, sign and publish new Android samples directly from the operator console and can regenerate samples on a schedule, producing fresh files to defeat hash-based detection while the underlying implant stays largely unchanged. Panda Workshop V5 added two-factor authentication for operators, and V6 added a phishing download-page builder; the panels also use AI to rank potential victims by value. Cleafy points to account limits and role-based access as further evidence of a commercial model in which customers buy a defined capacity. The significance for financial institutions is that the barrier to running an Android banking-trojan campaign has moved from development capability to a subscription, so the differentiator on the defensive side is detection and device-integrity telemetry rather than awareness of any single sample.

Attribute Detail
Sector Financial Services
Date 2026-09-30
Source Infosecurity Magazine
Reliability Tier 3