Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check

Technical Analysis
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of unauthorized installation on reachable devices and show how the malware uses dynamic loading to conceal its behavior. The sample also added a Frida detection check, reducing visibility for analysts who rely on instrumentation. The research provides concrete artifacts and behaviors that defenders can use to spot Hagaseca activity.

Related Happenings

THost9 Android RAT with embedded ADB worm

Malware Activity
H score22 First: 08.09.2026 14:15 Last: 08.09.2026 14:15 Sources 1

How related: A packed Android remote access trojan (RAT) has combined a concealed loader with a worm that scans for exposed Android Debug Bridge (ADB) services and installs itself on reachable devices.

About this happening: The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unau...

Timeline

  1. 08.09.2026 14:15 1 articles · 22h ago

    Researchers resolve the THost9 command-and-control host

    Detection Ioc Update

    Dark Atlas resolved THost9's command-and-control host on September 4 and found the endpoint still accepting the loader's connection sequence, indicating active infrastructure for the packed Android RAT.

    Show sources
  2. 08.09.2026 14:15 2 articles · 22h ago

    Dark Atlas dissects THost9 packed Android RAT with tc9.dex and an ADB worm

    Initial Disclosure

    Dark Atlas published research on September 8 dissecting THost9, a packed Android RAT that hides executable code inside an Android application package, loads tc9.dex, and uses an embedded ADB worm to discover exposed Android Debug Bridge services and install itself on reachable devices. The sample also added a Frida detection check, and the wider cluster was named Hagaseca from shared namespace, certificate, and class names.

    Show sources