Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hagaseca Android RAT spread via THost9 loader and ADB worm behavior

Malware Activity
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device control and expanding infection reach. The malware can maintain access through shell execution, file transfers, tunneling, and downloadable modules. That combination increases the risk of broader Android compromise and harder-to-remove footholds.

Related Happenings

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

RedHook Android malware abuses Wireless ADB for shell access

Malware Activity
H score26 First: 12.07.2026 17:27 Last: 12.07.2026 17:27 Sources 1

About this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...

Google Play Protect adds warnings and app disabling for compromised SDK abuse

Security Tool/Service
H score11 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

About this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

BTMOB Android RAT no-code builder malware activity

Malware Activity
H score28 First: 26.05.2026 17:00 Last: 26.05.2026 17:00 Sources 1

About this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...

Latest development: 29.05.2026 00:10

BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.

Timeline

  1. 10.09.2026 17:36 2 articles · 1h ago

    Hagaseca spreads through THost9 loader and exposed ADB services

    Initial Disclosure

    The Hagaseca Android remote access trojan is spread via the THost9 loader and a worm component that scans exposed Android Debug Bridge (ADB) services, then installs the malware for persistent remote control through shell execution, file transfers, tunneling, and downloadable modules.

    Show sources