Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check
Technical Analysis
Summary
Hide ▲
Show ▼
Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of unauthorized installation on reachable devices and show how the malware uses dynamic loading to conceal its behavior. The sample also added a Frida detection check, reducing visibility for analysts who rely on instrumentation. The research provides concrete artifacts and behaviors that defenders can use to spot Hagaseca activity.
Related Happenings
THost9 Android RAT with embedded ADB worm
Malware Activity
H score22
First: 08.09.2026 14:15
Last: 08.09.2026 14:15
Sources 1
How related:
A packed Android remote access trojan (RAT) has combined a concealed loader with a worm that scans for exposed Android Debug Bridge (ADB) services and installs itself on reachable devices.
About this happening:
The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unau...
THost9 Android RAT with embedded ADB worm
Malware ActivityHow related: A packed Android remote access trojan (RAT) has combined a concealed loader with a worm that scans for exposed Android Debug Bridge (ADB) services and installs itself on reachable devices.
About this happening: The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unau...
Timeline
-
08.09.2026 14:15 1 articles · 22h ago
Researchers resolve the THost9 command-and-control host
Detection Ioc UpdateDark Atlas resolved THost9's command-and-control host on September 4 and found the endpoint still accepting the loader's connection sequence, indicating active infrastructure for the packed Android RAT.
Show sources
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15
-
08.09.2026 14:15 2 articles · 22h ago
Dark Atlas dissects THost9 packed Android RAT with tc9.dex and an ADB worm
Initial DisclosureDark Atlas published research on September 8 dissecting THost9, a packed Android RAT that hides executable code inside an Android application package, loads tc9.dex, and uses an embedded ADB worm to discover exposed Android Debug Bridge services and install itself on reachable devices. The sample also added a Frida detection check, and the wider cluster was named Hagaseca from shared namespace, certificate, and class names.
Show sources
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15