INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

RatHat's C2 Panel Evolves into Malware-as-a-Service Model

| 2026-09-28 20:24 MEDIUM MEDIUM MALWARE & BOTNETS
Executive Summary
AI-generated
The RatHat Android banking trojan has been observed to have undergone significant changes in its command-and-control (C2) panel, with three generations of panels emerging over six months. The infrastructure behind the malware has evolved into a Malware-as-a-Service model, where operators can build and publish new samples directly from their console. Nearly 100 separate deployments since April 2026 have been observed, consistent with this model. The C2 panels use AI to rank potential victims based on estimated bank balances, sorting devices into high-value and mid-value groups for operator identification. This technique has also allowed operators to identify targets without reviewing every infected phone by hand.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
dr•••••.com
ra•••••.me
ww•••••.com
ad•••••.live
8fdc21••••••••••••••••••••••••••
116346••••••••••••••••••••••••••
f83357••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BlackCatBlackCat
Target & Sectors
EUROPE EUROPE LATAM LATAM APAC APAC financefinance manufacturingmanufacturing
Incident Timeline
‎late 2025
Threat actors behind BlackCat shifted to Panda Workshop, a rebranded C2 panel, approximately six months after the initial implant deployment in late 2025.
malware BlackCat
organisation Cleafy
‎April 2026
Nearly 100 separate deployments of malware since April 2026 are consistent with a malware-as-a-service model.
general_metric 100 separate deployments
‎September 2026
Threat actors using the BlackCat malware-as-a-service model updated its C2 panel to Panda Workshop, resulting in nearly 100 separate deployments across multiple regions.
malware BlackCat
organisation Cleafy
‎between April and September 2026
Threat actors behind BlackCat deployed successive Command-and-Control panel generations, including Panda Workshop V5 and V6, between April and September 2026.
malware BlackCat
organisation Command
‎September 28
Threat actors behind BlackCat rebranded their C2 panel as Panda Workshop, introducing a third generation of the control plane in approximately six months.
malware BlackCat
organisation Cleafy
‎2026/09/28
Threat actors used the Evolving C2 Panel behind RatHat to build, sign and publish new Android banking trojan samples directly from an operator console.
infrastructure Android
organisation Accessibility Service
organisation IP
organisation RatHat
organisation Evolving C2 Panel Points
organisation Workshop V5
organisation Google
Tactical Metrics
Metrics
infrastructure
‎Android
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-09-29