Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
Summary
Hide ▲
Show ▼
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device control and expanding infection reach. The malware can maintain access through shell execution, file transfers, tunneling, and downloadable modules. That combination increases the risk of broader Android compromise and harder-to-remove footholds.
Related Happenings
RatHat Android credential-theft malware
Malware Activity
H score27
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...
RatHat Android credential-theft malware
Malware ActivityAbout this happening: RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...
Latest development: 18.09.2026 09:17
Zimperium said RatHat pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the Android sandbox, unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware stages native daemons that execute with shell-level privileges, lets a Go Agent masquerading as liblocal-service.so apply persistence and power management exemptions, and can re-install itself through the local service after uninstall. The operator also uses an FRP reverse-proxy client to establish a persistent reverse tunnel to the C2 server, while the malware can record finger presses on screen with a hardware-level keylogger.
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical Analysis
H score28
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a new Android malware campaign analyzed by Zimperium zLabs and linked to China-based threat actors. It uses an AI-powered UI-automation subsystem to...
RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers
Technical AnalysisAbout this happening: RatHat is a new Android malware campaign analyzed by Zimperium zLabs and linked to China-based threat actors. It uses an AI-powered UI-automation subsystem to...
RatHat smishing-malvertising Android APK distribution campaign
Campaign
H score36
First: 17.09.2026 16:00
Last: 17.09.2026 16:00
Sources 1
About this happening:
RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
RatHat smishing-malvertising Android APK distribution campaign
CampaignAbout this happening: RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishin...
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
Timeline
-
10.09.2026 17:36 2 articles · 11d ago
Hagaseca spreads through THost9 loader and exposed ADB services
Initial DisclosureThe Hagaseca Android remote access trojan is spread via the THost9 loader and a worm component that scans exposed Android Debug Bridge (ADB) services, then installs the malware for persistent remote control through shell execution, file transfers, tunneling, and downloadable modules.
Show sources
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps — thehackernews.com — 10.09.2026 17:36
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps — thehackernews.com — 10.09.2026 17:36