Researchers at Dark Atlas identified THost9, a packed Android remote-access trojan associated with the artifact-defined Hagaseca cluster. A concealed loader decodes and dynamically loads the tc9.dex second-stage payload, enabling remote shell access, command execution, file transfers, tunneling, reverse shells, and downloadable modules.
THost9 contains a worm that scans broad address ranges or uses supplied targets to find exposed Android Debug Bridge (ADB) services, then uses prepared ADB key material to authenticate and install itself on reachable Android devices and Redroid containers. Incident reporting has linked THost9 and the earlier THost4 variant to exposed-ADB infections from October 2024 through 2026; organizations should remove public ADB exposure and examine accessibility services and persistent Redroid data for compromise.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Dark Atlas resolved the command-and-control host used by THost9 and found it had recently continued accepting the loader's connection sequence.
During an analyst check, the THost9 command-and-control endpoint was still accepting the loader's connection sequence.
Following an infection, a Redroid deployment was rebound to localhost-only access as part of remediation.
Public incident reports linked THost9 and the earlier THost4 variant to infections of Android phones and Redroid containers exposed through Android Debug Bridge services, with reports spanning from October 2024 through 2026.
Dark Atlas identified THost9 as a packed Android RAT and designated the broader artifact-defined cluster Hagaseca based on shared namespaces, certificates, and class names. Researchers reported that its tc9.dex payload includes an ADB worm that authenticates to accessible exposed ADB services with prepared key material and installs the malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.