darkatlas.io
THost9 Android RAT Exploits ADB Vulnerabilities for Remote Control
Article Content
The THost9 Android remote access trojan (RAT) has been identified as a significant threat, utilizing a packed loader to conceal its malicious payload. This malware exploits exposed Android Debug Bridge (ADB) services to install itself on vulnerable devices. Dark Atlas reported that THost9 hides executable code within an Android application package (APK) and loads a second-stage payload called tc9.dex, which provides extensive control capabilities. The malware can discover ADB services and propagate itself using a built-in worm feature, targeting a range of devices. Public incident reports have linked THost9 to infections on Android phones and Redroid containers since October 2024. The malware's command-and-control infrastructure was still active as of September 4, 2026, indicating ongoing exploitation. Dark Atlas has recommended immediate action to secure ADB services and review accessibility permissions to mitigate risks.
Key Points: • THost9 exploits exposed ADB services to install itself on Android devices. • The malware uses a packed loader to conceal its payload and features a built-in worm for propagation. • Public incident reports link THost9 to infections on Android phones and Redroid containers since 2024.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.