Skip to content
THost9 Android RAT Pairs Packed Loader With ADB Worm

THost9 Android RAT Pairs Packed Loader With ADB Worm

Infosecurity-Magazine • September 8, 2026

A packed Android remote access trojan (RAT) has combined a concealed loader with a worm that scans for exposed Android Debug Bridge (ADB) services and installs itself on reachable devices.

Dark Atlas said in research published on September 8 that the malware, which it tracks as THost9, hid executable code inside an Android application package before loading a second-stage payload called tc9.dex.

It named the wider cluster Hagaseca after the namespace, certificate and class names shared across the samples.

Packed Loader Hides the RAT

The packed loader used an embedded asset to conceal its executable code. Dark Atlas found the asset was decoded with a single-byte XOR operation and decompressed with gzip before the recovered payload was loaded dynamically.

The loader then started a foreground service, removed its activity from Android's Recents view and used a nearly blank notification. It could enable an accessibility service giving control over the device interface, but only where the protected settings permission had already been granted.

The second stage added shell execution, file transfers, tunneling, reverse-shell access and downloadable modules. Dark Atlas also found a local controller that accepted commands without authentication in one tested build, though it said binding to all interfaces did not prove the socket was reachable from the internet.

The researchers resolved the malware's command-and-control (C2) host on September 4 and said an analyst check the day before discovered the endpoint was still accepting the connection sequence the loader uses.

A newer build added an anti-analysis check for Frida, an instrumentation framework commonly used by security researchers. When the marker was detected, the sample exited.

ADB Worm Targets Exposed Devices

The most significant propagation feature was the ADB worm built into the second stage. Dark Atlas said it could discover ADB services through Android's local service-discovery mechanisms or accept operator-selected targets, then expand one address to a 65,025-host range and probe it with 50 workers.

It then authenticated using prepared ADB key material, retrieved the installer package and ran it. Where the remote session was privileged, it could alter ADB settings and ports and copy itself into a system directory.

Public incident reports connected THost9 and the earlier THost4 to Android phones and Redroid containers with exposed ADB, from the first located THost4 sample in October 2024 through to 2026. A July 2026 remediation rebound a Redroid deployment to localhost only after an infection.

Dark Atlas cautioned that scanning an ADB service does not by itself grant access. But it said incident records and the recovered scanner directly connect infections with public ADB or Redroid exposure.

The researchers named the package, its signing certificate and two private cache files as detection points, and urged removing public ADB exposure and reviewing accessibility services and persistent Redroid data.

They described Hagaseca as an artifact-defined cluster and said the evidence did not establish a verified threat-group identity.

Fake anti-virus jumps from PCs to Android News 24 June 2013

Fake anti-virus jumps from PCs to Android

Financial Brands Targeted in Global Mobile Banking Malware Surge News 19 March 2026

Financial Brands Targeted in Global Mobile Banking Malware Surge

RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026

RedWing Android Spyware Sold as a Service on Telegram

Rokarolla Trojan Combines Banking Fraud With Device Surveillance News 16 June 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

BTMOB Android RAT Spreads Through No-Code Builder Tooling News 26 May 2026

BTMOB Android RAT Spreads Through No-Code Builder Tooling

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

Multiple Class Action Lawsuits Filed Against IDScan

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

Attackers Steal METR API Key and Burn $600,000 in AI Credits

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

65% of Enterprises Have Seen AI Agents Act Out of Scope

Hiring for the AI Era: A New Challenge for CISOs

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Securing M365 Data and Identity Systems Against Modern Adversaries

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Predicting and Prioritizing Cyber Attacks Using Threat Intelligence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities