HomeRisk ManagementsTHost9 Android RAT Pairs Packed Loader with ADB Worm

THost9 Android RAT Pairs Packed Loader with ADB Worm

Published on

spot_img

New Android Remote Access Trojan Combines Persistent Loader and Worm for Device Exploitation

A recent investigation has unveiled a sophisticated Android remote access trojan (RAT) that combines a concealed loader with a worm designed to exploit exposed Android Debug Bridge (ADB) services. This alarming development highlights both the advances in malware technology and the significant risks posed to Android devices.

In a detailed research report published on September 8, the cybersecurity firm Dark Atlas tracked the malware under the designation THost9. Analysts discovered that this new strain of malware cleverly concealed executable code within an Android application package. At its core, the RAT incorporates a second-stage payload known as tc9.dex, which is loaded after the initial phase. The research team subsequently named the broader cluster "Hagaseca," owing to the shared namespace, certificate, and class names visible across various samples.

Concealed Loader: A Stealthy Threat Vector

The packed loader serves as the initial point of contact for this malware. Dark Atlas identified that the loader employs an embedded asset to hide its executable code. The research indicated that this asset undergoes a decoding process involving a single-byte XOR operation followed by decompression via gzip, allowing the payload to be dynamically loaded only when certain conditions are met.

Once activated, the loader initiates a foreground service that effectively removes its presence from Android’s Recents view, employing a nearly blank notification in a bid to remain undetected. The loader has the potential to enable an accessibility service, granting it control over the device’s interface, but only if the protected settings permission has been previously granted to it.

As the second stage unfolds, the level of control the malware exerts escalates dramatically. It offers capabilities such as shell execution, file transfers, tunneling, reverse-shell access, and the ability to download additional modules. Notably, Dark Atlas discovered a local controller capable of accepting commands without any form of authentication in one of the tested builds, although it is unclear whether the socket could be accessed from the internet as it bound to all interfaces.

The ADB Worm: A Threat of Scale

The most significant aspect of this malware, according to Dark Atlas, is its ADB worm, which serves as a primary mechanism for propagation. This worm can uncover ADB services using Android’s local service-discovery tools or can be directed towards operator-selected targets. The malware is equipped to expand a single address into a vast range encompassing 65,025 hosts and probes this range with as many as 50 worker processes.

By authenticating using prepared ADB key material, the worm retrieves the installer package and executes it. In instances where the remote session possesses privileged access, it can modify ADB settings and ports, allowing it to embed itself within a system directory.

Public incident reports have linked the THost9 strain to Android devices and Redroid containers with exposed ADB services. The timeline of these reports stretches from the first identified THost4 sample in October 2024 all the way through 2026, revealing an alarming trend in the malware’s evolution and persistence. Notably, a remediation effort in July 2026 led to a Redroid deployment reverting to localhost only after an infection had occurred.

Urgent Recommendations for Mitigation

Dark Atlas has advised that simply scanning an ADB service does not automatically grant unauthorized access. However, the researchers emphasized that a correlation exists between incident records and documented infections that stem from public ADB or Redroid exposures.

The team identified specific points for detection: the package, its signing certificate, and two private cache files. They strongly recommend that users take proactive measures to remove public ADB exposure and meticulously review accessibility services, alongside any persistent Redroid data that may remain.

Furthermore, Dark Atlas characterized the Hagaseca cluster as an artifact-defined grouping, cautioning that the evidence presented does not conclusively establish a verified threat-group identity. This absence of a clear affiliation poses an additional layer of complexity in addressing the threat.

In closing, the emergence of the THost9 RAT signifies an evolving landscape of cybersecurity threats, particularly for Android users. The combination of advanced concealment techniques and extensive propagation methods serves as a wake-up call for device security and the need for vigilant monitoring and protective measures. Users are urged to remain cautious and implement recommended security protocols to safeguard against such evolving threats.

Source link

Latest articles

Breaking Down Data Barriers for More Efficient and Intelligent Policing

A Public Sector Session from Elastic ...

Up to 10x More Coverage Compared to Traditional Pentests

Boston, MA, USA, September 8th, 2026, CyberNewswire Reflectiz, a prominent player in continuous web exposure...

BigBear 2.0 Phishing Campaign Compromises Microsoft 365 Sessions Post-MFA

Title: Rising Phishing Threats Require Prompt Action for Cybersecurity Defense In light of recent cybersecurity...

Adobe Commerce Max-Severity Bug Under Active Attack

Adobe Issues Emergency Hotfix for Vulnerability Exploited by Cybercriminals In recent developments, Adobe has urgently...

More like this

Breaking Down Data Barriers for More Efficient and Intelligent Policing

A Public Sector Session from Elastic ...

Up to 10x More Coverage Compared to Traditional Pentests

Boston, MA, USA, September 8th, 2026, CyberNewswire Reflectiz, a prominent player in continuous web exposure...

BigBear 2.0 Phishing Campaign Compromises Microsoft 365 Sessions Post-MFA

Title: Rising Phishing Threats Require Prompt Action for Cybersecurity Defense In light of recent cybersecurity...