logo

THost9 Android RAT Pairs Packed Loader With ADB Worm

ID: dd610e9b-edd8-5c47-ac33-0c14690e7c26

STIX ID: report--dd610e9b-edd8-5c47-ac33-0c14690e7c26

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-09-08

Date Updated: 2026-09-11

...
...

Dark Atlas analyzed an Android remote-access trojan (THost9) within the Hagaseca cluster that uses a packed loader (XOR + gzip) to deploy a second-stage payload (tc9.dex) offering shell execution, file transfer, tunneling, modules and a remote controller. The second-stage includes an ADB worm that discovers exposed ADB/Redroid services, probes large address ranges with concurrent workers, authenticates using prepared ADB keys, and installs itself — potentially altering ports and copying to system directories; researchers observed active C2 behavior, anti-analysis checks (Frida), and recommended removing public ADB exposure and inspecting accessibility services and persistent Redroid data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.