RatHat's AI navigation assistant is Google Gemini
Assessment
Zimperium's own report explicitly declines to name which generative AI assistant RatHat communicates with, describing it only as "one of the world's most popular generative AI assistants." Infosecurity Magazine's review of the report notes that an architecture diagram included in Zimperium's analysis "suggests" the threat actors used Google's Gemini models — but this is the journalist's inference from a diagram, not a named conclusion stated by the researchers. No other outlet reviewed for this paper repeats a Gemini attribution. A reader who encounters "RatHat uses Gemini" stated as fact would be repeating an inference one step removed from the primary source's actual, deliberately unspecific, claim.
Where this claim appeared
Infosecurity Magazine · 2026-09-17
https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
RatHat: AI-Driven Android Malware Abuses Wireless Debugging to Steal Banking CredentialsThink this assessment is wrong? Report an error.