Back to Intelligence

RATHat Android Banking Trojan: From BlackCat Panel to Panda Workshop — ADB Exploitation C2 Detection Pack

SA
Security Arsenal Team
September 29, 2026
10 min read

A new pulse published to AlienVault OTX by AlienVault Labs (drawing on Cleafy research) documents the evolution of the RATHat Android banking trojan and its command-and-control panel — which has been traced from the original BlackCat panel to a rebranded successor known as Panda Workshop. RATHat is operated as a Malware-as-a-Service (MaaS) offering, with the operator's primary investment concentrated in C2 infrastructure, panel automation, and reportedly AI-powered automation for campaign management and victim interaction.

RATHat's architecture is distinctive: the malicious APK is merely an entry point. Once the victim grants Accessibility Service permissions, the trojan silently enables wireless debugging, pairs with the device's own ADB daemon, and deploys a native Go service that executes entirely outside Android's permission and sandbox model. This gives the operator unrestricted, root-equivalent device control without triggering the permission prompts or Play Protect heuristics that most Android banking trojans must evade. Targeted industry telemetry points to the finance sector, consistent with the trojan's overlay, credential interception, and on-device fraud capabilities.

The campaign's objective is full on-device fraud enablement: banking credential theft, session hijacking, and automated transaction fraud delivered through a polished, subscription-based MaaS panel. The BlackCat-to-Panda-Workshop rebranding signals a mature operator actively maintaining and marketing the platform rather than abandoning burned infrastructure.

Threat Actor / Malware Profile

Malware family: RATHat (Android banking trojan / RAT) Operator model: MaaS — panel evolved from BlackCat to Panda Workshop Attribution: Unknown actor, infrastructure consistent with organized cybercrime rather than nation-state activity

Distribution: Dropper APKs delivered via social engineering lures (phishing pages masquerading as legitimate apps), with a live distribution URL observed at rathat.me serving app-release-rat-hat-live.apk and lure pages hosted on unrelated parked domains (e.g., dramaspoolcoa.com/en.html).

Payload behavior:

  1. Dropper APK requests Accessibility Service access under benign pretext
  2. Accessibility abuse is used to auto-grant follow-on permissions and suppress warnings
  3. The trojan enables Android wireless debugging (ADB over TCP, default port 5555) and pairs the device with itself
  4. A native Go binary is pushed and executed via ADB, running as a shell-privileged service outside the Android permission model
  5. Full device control: screen streaming, input injection, overlay injection, SMS/notification interception, and credential harvesting from banking apps

C2 communication: Administrative panel infrastructure observed on admin.chunhuating.best, admin.xiongmaocs.pics, and admin.rathat.live — consistent with a multi-tenant MaaS panel (Panda Workshop) serving multiple affiliates. HTTPS-based beaconing with domain rotation across low-reputation TLDs (.best, .pics, .live).

Persistence: The native Go service runs as an ADB-spawned shell process and survives app-level removal of the dropper APK. Wireless debugging state and pairing grants persist across reboots unless explicitly revoked.

Anti-analysis: Separation of dropper and payload frustrates static APK analysis (the APK contains minimal malicious logic). Native Go compilation resists common Android sandbox instrumentation, and execution outside the permission model bypasses runtime permission-based detection used by mobile EDR tools.

IOC Analysis

The pulse contains 8 indicators across four types:

TypeIndicatorsOperationalization
Hostnameadmin.chunhuating.best, admin.xiongmaocs.pics, admin.rathat.liveSinkhole/block at DNS resolver and web proxy; alert on any resolution. Panel-admin hostnames indicate affiliate or operator traffic if seen from corporate assets.
URLhttps://dramaspoolcoa.com/en.html, https://rathat.me/app-release-rat-hat-live.apkBlock at secure web gateway; hunt proxy logs for APK downloads. The lure URL is a social-engineering landing page — flag user visits for follow-up.
FileHash-MD5116346cace7f00ba557034b534d40791, 8fdc21e25097a46528211274e54330e1, f83357b2d47c7d38ee53943373961211Load into EDR/mobile MTD blocklists; submit to a sandbox (VirusTotal, Joe Sandbox, MobSF) to confirm payload lineage. MD5s rotate quickly — treat as point-in-time artifacts.

Tooling guidance: Enrich hostnames via passive DNS (SecurityTrails, PassiveTotal, OTX) to surface sibling panel domains — MaaS operators rotate on predictable naming patterns. Use MobSF or jadx for APK triage and apktool for manifest inspection (look for BIND_ACCESSIBILITY_SERVICE and debug bridge abuse). Network-side, alert on outbound connections from Android devices to non-standard destinations and on any internal host resolving the panel domains. Because the payload pivots through ADB, DNS/proxy telemetry alone is insufficient — pair with mobile device management (MDM) telemetry flagging devices with wireless debugging enabled.

Detection Engineering

The following detections target the behaviors central to this campaign: ADB/wireless-debugging abuse, Go-native payload execution, and C2 panel communication. The Sigma rules cover network DNS indicators, suspicious ADB process lineage, and shell-level execution of dropped binaries — all applicable to mobile device lab environments, Android emulators in CI, and corporate-owned Android fleets monitored via EDR bridges.

YAML
---
title: RATHat / Panda Workshop C2 Panel Domain Resolution
id: 7f3a2c1e-9b4d-4e6a-8c1f-2d5b7a9e0011
status: experimental
description: Detects DNS resolution of known RATHat / Panda Workshop MaaS panel and distribution domains associated with the Android banking trojan campaign.
author: Security Arsenal Threat Intelligence
references:
    - https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
logsource:
    category: dns
detection:
    selection:
        query|contains:
            - 'admin.chunhuating.best'
            - 'admin.xiongmaocs.pics'
            - 'admin.rathat.live'
            - 'rathat.me'
            - 'dramaspoolcoa.com'
    condition: selection
falsepositives:
    - Threat intelligence research or sandbox detonation of samples
level: high
tags:
    - attack.command_and_control
    - attack.t1071
date: 2026/09/29
---
title: Suspicious ADB Wireless Debugging and Shell Execution Activity
id: 8a4b3d2f-1c5e-4f7b-9d2a-3e6c8b0f0022
status: experimental
description: Detects ADB daemon invocation patterns consistent with RATHat's self-pairing wireless debugging abuse, including ADB spawning shell processes or pushing/executing native binaries.
author: Security Arsenal Threat Intelligence
references:
    - https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
logsource:
    category: process_creation
    product: windows
detection:
    selection_adb_exec:
        Image|endswith: '\adb.exe'
        CommandLine|contains:
            - 'connect'
            - 'pair'
            - 'push'
            - 'shell'
    selection_shell_payload:
        ParentImage|endswith:
            - '\adb.exe'
            - 'adbd'
        CommandLine|contains:
            - 'chmod 755'
            - '/data/local/tmp'
            - 'nohup'
    condition: 1 of selection_*
falsepositives:
    - Legitimate Android development and QA activity
    - MDM provisioning tooling
level: high
tags:
    - attack.execution
    - attack.t1059
    - attack.command_and_control
    - attack.t1572
date: 2026/09/29
---
title: Native Go Payload Execution from Android Writable Directories
id: 9c5d4e3a-2d6f-4a8c-0e3b-4f7d9c1a0033
status: experimental
description: Detects execution of unsigned binaries from world-writable Android staging directories (e.g., /data/local/tmp), the deployment pattern used by RATHat's native Go service after ADB pairing.
author: Security Arsenal Threat Intelligence
references:
    - https://www.cleafy.com/cleafy-labs/from-blackcat-to-panda-workshop-inside-the-evolving-c2-panel-behind-rathat
logsource:
    category: process_creation
    product: linux
detection:
    selection:
        CommandLine|contains:
            - '/data/local/tmp/'
            - '/sdcard/Download/'
    filter_known_tools:
        CommandLine|contains:
            - 'frida'
            - 'magisk'
    condition: selection and not filter_known_tools
falsepositives:
    - Mobile security research tooling
    - Custom enterprise Android instrumentation
level: medium
tags:
    - attack.execution
    - attack.t1059
    - attack.defense_evasion
    - attack.t1222
date: 2026/09/29
KQL — Microsoft Sentinel / Defender
// RATHat / Panda Workshop — IOC and behavioral hunt for Microsoft Sentinel
// Hunts network indicators and ADB-adjacent process behavior across managed endpoints.
let RATHatDomains = dynamic(["admin.chunhuating.best", "admin.xiongmaocs.pics", "admin.rathat.live", "rathat.me", "dramaspoolcoa.com"]);
let RATHatHashes = dynamic(["116346cace7f00ba557034b534d40791", "8fdc21e25097a46528211274e54330e1", "f83357b2d47c7d38ee53943373961211"]);
union isfuzzy=true
    (DeviceNetworkEvents
    | where TimeGenerated > ago(14d)
    | where RemoteUrl has_any (RATHatDomains)
    | project TimeGenerated, DeviceName, RemoteUrl, RemoteIP, InitiatingProcessFileName, InitiatingProcessCommandLine, IndicatorType="C2/Panel DNS"
    ),
    (DeviceFileEvents
    | where TimeGenerated > ago(14d)
    | where MD5 in (RATHatHashes)
    | project TimeGenerated, DeviceName, FolderPath, FileName, MD5, InitiatingProcessFileName, IndicatorType="Known RATHat Sample Hash"
    ),
    (DeviceProcessEvents
    | where TimeGenerated > ago(14d)
    | where (FileName =~ "adb.exe" and ProcessCommandLine has_any ("pair", "connect", "push", "shell"))
       or (InitiatingProcessFileName =~ "adb.exe" and ProcessCommandLine has_any ("/data/local/tmp", "chmod", "nohup"))
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName, IndicatorType="ADB Abuse Pattern"
    )
| order by TimeGenerated desc
PowerShell
# RATHat / Panda Workshop IOC Hunt — Security Arsenal
# Checks endpoint DNS cache, established connections, and proxy-visible artifacts
# for RATHat panel/distribution infrastructure. Run elevated; suitable for fleet-wide
# execution via RMM/Intune/EDR live response.

$panelDomains = @(
    'admin.chunhuating.best',
    'admin.xiongmaocs.pics',
    'admin.rathat.live',
    'rathat.me',
    'dramaspoolcoa.com'
)
$knownHashes = @(
    '116346cace7f00ba557034b534d40791',
    '8fdc21e25097a46528211274e54330e1',
    'f83357b2d47c7d38ee53943373961211'
)

Write-Output "=== RATHat IOC Hunt — $(Get-Date -Format 'yyyy-MM-dd HH:mm') ==="

# 1) DNS cache hits for panel/distribution domains
Write-Output "`n[1] DNS Cache Check"
$dnsHits = Get-DnsClientCache -ErrorAction SilentlyContinue |
    Where-Object { $d = $_.Entry; $panelDomains | Where-Object { $d -like "*$_*" } }
if ($dnsHits) { $dnsHits | Format-Table Entry, Data, Status -AutoSize } else { Write-Output "No panel domains in DNS cache." }

# 2) Active connections to resolved panel infrastructure
Write-Output "`n[2] Active Network Connections"
$resolved = foreach ($dom in $panelDomains) {
    try { (Resolve-DnsName $dom -ErrorAction Stop).IPAddress } catch { $null }
}
if ($resolved) {
    Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
        Where-Object { $resolved -contains $_.RemoteAddress } |
        ForEach-Object {
            $proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
            [PSCustomObject]@{ RemoteIP=$_.RemoteAddress; Port=$_.RemotePort; Process=$proc.ProcessName; PID=$_.OwningProcess }
        } | Format-Table -AutoSize
} else { Write-Output "Panel domains did not resolve locally (may already be sinkholed)." }

# 3) ADB presence and suspicious ADB usage on workstation fleets (dev/QA risk surface)
Write-Output "`n[3] ADB Process / Staging Artifacts"
$adb = Get-Process -Name 'adb' -ErrorAction SilentlyContinue
if ($adb) {
    $adb | ForEach-Object { Write-Output "ADB RUNNING: PID $($_.Id) Path $($_.Path)" }
} else { Write-Output "No adb.exe processes running." }

# 4) File hash sweep of common download/drop locations
Write-Output "`n[4] Hash Sweep — Downloads/Desktop/Temp"
$paths = @("$env:USERPROFILE\Downloads", "$env:USERPROFILE\Desktop", $env:TEMP)
foreach ($p in $paths) {
    if (Test-Path $p) {
        Get-ChildItem $p -Recurse -File -Include *.apk,*.exe,*.bin -ErrorAction SilentlyContinue |
            ForEach-Object {
                $h = (Get-FileHash $_.FullName -Algorithm MD5 -ErrorAction SilentlyContinue).Hash
                if ($knownHashes -contains $h.ToLower()) {
                    Write-Output "MATCH: $($_.FullName) — MD5 $h"
                }
            }
    }
}

Write-Output "`n=== Hunt complete. Escalate any hits to IR per playbook. ==="

Response Priorities

Immediate (0–4h):

  • Block all panel and distribution domains (admin.chunhuating.best, admin.xiongmaocs.pics, admin.rathat.live, rathat.me, dramaspoolcoa.com) at DNS resolver, secure web gateway, and proxy; add the three MD5 hashes to EDR and mobile threat defense blocklists.
  • Hunt proxy and DNS telemetry for the last 30 days for any resolution of the listed domains — panel-admin hostnames on corporate assets indicate potential affiliate activity or a compromised researcher environment.
  • For managed Android fleets: query MDM for any device with wireless debugging enabled or developer options active outside the approved developer population — this is the single highest-fidelity RATHat precursor signal.
  • Quarantine any device that downloaded an APK from an untrusted source in the hunt window.

24 Hours:

  • RATHat is credential-stealing, session-hijacking banking malware: any user whose device shows exposure (lure URL visit, APK install, or ADB anomaly) requires full credential reset — banking, email, SSO, and any app authenticated on the device — plus revocation of active sessions and OAuth tokens.
  • Force re-enrollment of MFA on affected identities; assume SMS-based OTP on the compromised device is intercepted and migrate those users to app-based or hardware MFA.
  • Review financial transaction logs for affected users for anomalous transfers consistent with on-device fraud (transactions originating from the legitimate device and session).
  • Interview users who visited the lure URL to establish delivery vector (smishing, malvertising, or messaging-app lure) and feed findings back into filtering controls.

1 Week:

  • Enforce MDM policy disabling developer options and wireless ADB debugging on all non-developer Android devices; alert on policy tampering.
  • Implement or tighten Android Enterprise/Work Profile policies restricting sideloading (install_unknown_sources) and Accessibility Service grants to an allowlist of approved apps.
  • Deploy mobile threat defense capable of detecting ADB-spawned native processes and Accessibility abuse, since network-only controls miss the on-device pivot.
  • Add passive-DNS monitoring rules for the Panda Workshop naming pattern (admin.* on .best/.pics/.live TLDs) to catch the next infrastructure rotation, and subscribe to the Cleafy/OTX pulse feed for hash updates.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.