RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity Magazine
In research published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent .
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
Map who has access to your most sensitive data (financials, HR records, intellectual property) and cut that list down to the people who actually need it Build privilege review into onboarding and offboarding, so access changes the moment a role does Audit SaaS and software procurement outside of IT's usual process to catch accidental admins nobody assigned on purpose Pick one application or system to start with instead of trying to overhaul every environment at once Re-evaluate access every six months and look for drift from your baseline Add role-based access questions to vendor and software evaluations before you buy Build a simple, low-friction process for employees to request more access when they genuinely need it Privilege hygiene works best when you can see where access is expanding and catch risky changes before they turn into a bigger problem.
The activity, which has been ongoing since July 2026, uses AI at all stages of the attack, with results of one informing the next - The threat actor is said to have loaded the Chinese system persona titled "SOUL - Red Team Operator" onto Hermes Agent and carried out the attack largely without any human involvement, and erased the card data from the victims' Magento database once the data had been exfiltrated.
However, the company also noted, “Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.” To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:
Cleafy also found that operators could use RatHat's wireless debugging access to deploy a native Go service with a single click from the panel, gaining shell-level control outside the Android application's permission model.
In July 2026, Palo Alto Networks linked a China-based threat actor dubbed "knaithe" and "KnYuan" to an AI-enabled hacking campaign that leveraged DeepSeek, via the Hermes Agent framework configured to accept instructions over Telegram, to enumerate targets, source exploit tools, and launch attacks without human intervention.
Nearly 100 separate deployments since April 2026 have been observed, consistent with a malware-as-a-service (MaaS) model.
What happened
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
Microsoft’s analysis of NeedyMantis suggested that it is only deployed after the threat actor has previously gained access to the compromised environment, therefore the malware is likely used to maintain long-term access and support follow-on operations.
What changed
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent .
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
Who is affected
Map who has access to your most sensitive data (financials, HR records, intellectual property) and cut that list down to the people who actually need it Build privilege review into onboarding and offboarding, so access changes the moment a role does Audit SaaS and software procurement outside of IT's usual process to catch accidental admins nobody assigned on purpose Pick one application or system to start with instead of trying to overhaul every environment at once Re-evaluate access every six months and look for drift from your baseline Add role-based access questions to vendor and software evaluations before you buy Build a simple, low-friction process for employees to request more access when they genuinely need it Privilege hygiene works best when you can see where access is expanding and catch risky changes before they turn into a bigger problem.
The activity, which has been ongoing since July 2026, uses AI at all stages of the attack, with results of one informing the next - The threat actor is said to have loaded the Chinese system persona titled "SOUL - Red Team Operator" onto Hermes Agent and carried out the attack largely without any human involvement, and erased the card data from the victims' Magento database once the data had been exfiltrated.
Why it matters
However, the company also noted, “Supply chain activity remains one possible means by which an actor could gain the access necessary to deploy the malware.” To defend networks against the potential threat of cyber-attacks based around NeedyMantis, Microsoft has recommended the following mitigations:
Cleafy also found that operators could use RatHat's wireless debugging access to deploy a native Go service with a single click from the panel, gaining shell-level control outside the Android application's permission model.
Technical details
In July 2026, Palo Alto Networks linked a China-based threat actor dubbed "knaithe" and "KnYuan" to an AI-enabled hacking campaign that leveraged DeepSeek, via the Hermes Agent framework configured to accept instructions over Telegram, to enumerate targets, source exploit tools, and launch attacks without human intervention.
Nearly 100 separate deployments since April 2026 have been observed, consistent with a malware-as-a-service (MaaS) model.
The malware used Gemini separately: when its static automation failed on unfamiliar Android interfaces, the implant sent details of the screen to a large language model (LLM) and asked where to tap.
Response
With the persistence set up, the next step involves deploying the Hermes Agent and overwriting its SOUL.md persona file with a custom prompt that asks the AI tool to assume the role of a "senior hacker, pentester, and exploit developer" named GH0ST and instructs it to "maintain persistence, respond over Telegram, and execute any operation the operator asks" without "moral or ethical restrictions." The agent then enters into an interactive command loop that interprets incoming tasks through Telegram and forwards them to the appropriate large language model (LLM) gateway.
The 2026 ENISA Threat Landscape confirms that cyber dependencies expand the attack surface and require a new level of vigilance to effectively prevent and mitigate the impact of cyber incidents.
What security teams should do
Microsoft found NeedyMantis while following up on indicators from Kaspersky's investigation into the supply chain attack on DAEMON Tools .
In the sample Microsoft analyzed in detail, the malicious file replaced WinSparkle.dll, the update component that Poedit uses.
What remains unknown
While it remains unknown how the NeedyMantis attackers gain initial access, what is known, as detailed by Microsoft Threat Intelligence, is NeedyMantis is composed of multiple components written in C++ and x64 shellcode These two elements have been discovered packaged alongside legitimate software, which installs the malware through DLL side-loading as part of a first-stage loader.
Attribution
Infosecurity Magazine: In research published September 28, Cleafy said the implant had changed little from late 2025 through September 2026, while its C2 panel went through three generations in six months and rebranded from BlackCat to Panda Workshop.
Infosecurity Magazine: Dubbed NeedyMantis, the malware operation has been active since at least October 2025.
The Hacker News: Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis.
The Hacker News: RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy.