Find notable cyber news and cases, enriched with sources, timelines, and signals.

THost9 Android RAT with embedded ADB worm

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unauthorized installs on reachable devices. The payload is loaded from tc9.dex, and the wider cluster is tracked as Hagaseca. The second stage adds shell execution, file transfers, tunneling and reverse-shell access.

Related Happenings

Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check

Technical Analysis
H score26 First: 08.09.2026 14:15 Last: 08.09.2026 14:15 Sources 1

How related: Dark Atlas said in research published on September 8 that the malware, which it tracks as THost9, hid executable code inside an Android application package before loading a second-stage payload called tc9.dex.

About this happening: Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of...

Timeline

  1. 08.09.2026 14:15 1 articles · 22h ago

    Dark Atlas resolves THost9 command-and-control host

    Detection Ioc Update

    Dark Atlas resolved THost9's command-and-control host on September 4, and an analyst check the day before found the endpoint was still accepting the connection sequence used by the loader.

    Show sources
  2. 08.09.2026 14:15 2 articles · 22h ago

    Dark Atlas details THost9 packed Android RAT and ADB worm

    Initial Disclosure

    Dark Atlas's September 8 research describes THost9 as a packed Android RAT that hides executable code in an APK, loads tc9.dex, and uses a concealed loader plus an embedded ADB worm. The cluster is tracked as Hagaseca, newer builds added a Frida anti-analysis check, and the researchers named the package, signing certificate, and two private cache files as detection points while urging removal of public ADB exposure and review of accessibility services and persistent Redroid data.

    Show sources