Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
Summary
Hide ▲
Show ▼
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device control and expanding infection reach. The malware can maintain access through shell execution, file transfers, tunneling, and downloadable modules. That combination increases the risk of broader Android compromise and harder-to-remove footholds.
Related Happenings
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/Service
H score11
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Google Play Protect adds warnings and app disabling for compromised SDK abuse
Security Tool/ServiceAbout this happening: Google Play Protect was updated in July 2026 to warn Android users automatically and disable apps tied to compromised SDKs, limiting abuse of consumer devices...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware Activity
H score25
First: 27.05.2026 19:10
Last: 27.05.2026 19:10
Sources 1
About this happening:
BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware ActivityAbout this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
BTMOB Android RAT no-code builder malware activity
Malware Activity
H score28
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: BTMOB is an Android RAT sold as malware-as-a-service on the clearweb and in private Telegram channels, with a no-code APK builder that generates customized...
Latest development: 29.05.2026 00:10
BTMOB is openly advertised on the clearweb and in private Telegram channels as a malware-as-a-service (MaaS) platform with an APK builder that customizes phishing payloads without coding. The Android RAT targets users mainly in Brazil and Latin America, uses phishing sites masquerading as streaming services, cryptocurrency mining platforms, and Google Play portals, and custom lures have included an Argentinian government agency theme.
Timeline
-
10.09.2026 17:36 2 articles · 1h ago
Hagaseca spreads through THost9 loader and exposed ADB services
Initial DisclosureThe Hagaseca Android remote access trojan is spread via the THost9 loader and a worm component that scans exposed Android Debug Bridge (ADB) services, then installs the malware for persistent remote control through shell execution, file transfers, tunneling, and downloadable modules.
Show sources
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps — thehackernews.com — 10.09.2026 17:36
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps — thehackernews.com — 10.09.2026 17:36