THost9 Android RAT with embedded ADB worm
Malware Activity
Summary
Hide ▲
Show ▼
The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unauthorized installs on reachable devices. The payload is loaded from tc9.dex, and the wider cluster is tracked as Hagaseca. The second stage adds shell execution, file transfers, tunneling and reverse-shell access.
Related Happenings
Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check
Technical Analysis
H score26
First: 08.09.2026 14:15
Last: 08.09.2026 14:15
Sources 1
How related:
Dark Atlas said in research published on September 8 that the malware, which it tracks as THost9, hid executable code inside an Android application package before loading a second-stage payload called tc9.dex.
About this happening:
Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of...
Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check
Technical AnalysisHow related: Dark Atlas said in research published on September 8 that the malware, which it tracks as THost9, hid executable code inside an Android application package before loading a second-stage payload called tc9.dex.
About this happening: Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of...
Timeline
-
08.09.2026 14:15 1 articles · 22h ago
Dark Atlas resolves THost9 command-and-control host
Detection Ioc UpdateDark Atlas resolved THost9's command-and-control host on September 4, and an analyst check the day before found the endpoint was still accepting the connection sequence used by the loader.
Show sources
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15
-
08.09.2026 14:15 2 articles · 22h ago
Dark Atlas details THost9 packed Android RAT and ADB worm
Initial DisclosureDark Atlas's September 8 research describes THost9 as a packed Android RAT that hides executable code in an APK, loads tc9.dex, and uses a concealed loader plus an embedded ADB worm. The cluster is tracked as Hagaseca, newer builds added a Frida anti-analysis check, and the researchers named the package, signing certificate, and two private cache files as detection points while urging removal of public ADB exposure and review of accessibility services and persistent Redroid data.
Show sources
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15
- THost9 Android RAT Pairs Packed Loader With ADB Worm — www.infosecurity-magazine.com — 08.09.2026 14:15