New Android Malware THost9 Uses Hidden Loader and Worm to Spread via Exposed Debug Services
Security researchers at Dark Atlas have identified a new Android threat called THost9, part of a wider malware cluster they refer to as Hagaseca. The malware disguises its malicious code inside an Android app package, decoding and loading a hidden second-stage payload only after installation. Once active, it hides itself from the device's recent apps view and can gain control over the device's interface if certain permissions are already enabled.
The second stage gives attackers a wide range of remote control capabilities, including running commands, transferring files, and creating hidden network tunnels. Most concerning is a built-in worm feature that scans networks for devices with Android Debug Bridge (a tool typically used by developers) left exposed. When found, the malware can automatically install itself onto these devices without needing a password, and in some cases modify system settings to embed itself more deeply.
Dark Atlas also found the malware includes checks designed to detect and avoid security researchers' analysis tools, suggesting its developers are actively trying to evade detection. The command-and-control server used to control infected devices was still active as of early September, according to the researchers.