Inside a Packed Android RAT Loader
released on 2026-09-08 @ 04:59:09 PM
Hagaseca is an Android malware cluster linked to exposed Android Debug Bridge (ADB) services, focusing on the THost9 RAT loader variant. The malware conceals executable code within an APK that loads tc9.dex, a stage providing shell access, file transfer, and ADB propagation capabilities. Public incidents connect THost4 and THost9 to exposed Android and Redroid systems from October 2024 through 2026. The loader uses XOR and gzip packing, establishes persistence through foreground services, exploits accessibility features for device control, and downloads additional stages from test.hagaseca.com. The tc9.dex stage implements remote administration, discovers ADB endpoints via mDNS, scans entire /16 networks, authenticates with prepared keys, and installs itself on vulnerable systems. The malware exhibits worm-like behavior, spreading opportunistically through unsecured ADB services exposed to the internet, particularly affecting Redroid container deployments and devices with public ADB over Wi-Fi.