From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat

Reported 28 Sep 2026 by otx · Severity: medium

RATHat is an Android banking trojan characterized by its unique architecture where the malicious application serves merely as an entry point. After obtaining Accessibility Service permissions, it enables wireless debugging, pairs with the device's ADB daemon, and deploys a native