Low-confidence report
This report is hidden because you're viewing high- and medium-confidence reports only. It isn't counted in the scores you're seeing.
Leaderboard / Case No. FB-2026-09-28-google-rathat-banking-trojan-victim-ranking
The RATHat Android banking trojan uses Gemini to rank infected phones by the bank balances in their text messages and to tell the malware where to tap on screen when its automation fails, across nearly 100 deployments since April 2026.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 5 | 18 USC 1030(a)(2)(C) |
| × Contribution | 2 | Ran the operation: Cleafy says the console asks Gemini to extract bank balances from all stolen SMS and score each device, "deciding which victims are worth an operator's time", and the malware sends the live screen tree to Gemini Flash models from the phone and receives the coordinates to tap; Gemini runs live inside the attack loop, though the malware performs the taps. |
| × Blast Radius | 1 | Third party: The victims are members of the public whose phones were infected via malvertising and smishing. |
| × Legal status | 1 | Crime. |
| + Tradecraft | 0 | The credential and SMS theft is done by the malware itself; Gemini's jobs (victim ranking and screen navigation) aren't rubric techniques. |
| + Guardrails | 0 | Guardrails intact: Operators use ordinary Google AI Studio API keys; no jailbreak or safety bypass is described. |
| + Dwell Time | 3 | Cleafy doesn't say when the Gemini features were first used, only that the console has had nearly 100 deployments since April 2026 and that V6 consolidated its AI on Gemini, so date_precision is before, using the report date (2026-09-28); dwell is counted from that latest possible date (0 days) and never inflated. Cleafy, a third party, found it. |
| Total | 13 |
Charges the human could face
18 USC 1030(a)(2)(C)Up to 5 years