Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new Android remote access trojan (RAT), tracked as THost9 and part of the Hagaseca cluster, employs a concealed loader and an ADB worm to install itself on vulnerable devices with exposed Android Debug Bridge services.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware utilizes a packed loader that hides executable code within an Android application package, decoding it with a single-byte XOR operation and decompressing it with gzip.
The packed loader hides executable code within an Android application package, decoding it with a single-byte XOR operation and decompressing it with gzip.
The loader then started a foreground service, removed its activity from Android's Recents view and used a nearly blank notification.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android remote-access trojan with a packed, XOR-decoded and gzip-decompressed loader that dynamically loads the tc9.dex second-stage payload. It supports shell execution, file transfer, tunneling, and reverse-shell access, and propagates by scanning for exposed ADB services, authenticating with prepared key material, and installing itself.
Packed Android remote-access trojan with a concealed loader and second-stage payload. It supports shell execution, file transfers, tunneling, reverse-shell access, downloadable modules, optional accessibility-service control, and unauthenticated local-controller commands in one tested build. Its integrated ADB worm discovers or targets exposed ADB services, scans expanded address ranges, authenticates using prepared ADB keys, and installs the malware on reachable devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.