Security News

New Android Malware THost9 Uses Hidden Loader and Worm to Spread via Exposed Debug Services

Infosecurity Magazine · 8 Sept 2026
Key Takeaway Businesses using Android devices, especially in development or testing environments, should ensure Android Debug Bridge access is disabled or restricted to trusted networks only.

Security researchers at Dark Atlas have identified a new Android threat called THost9, part of a wider malware cluster they refer to as Hagaseca. The malware disguises its malicious code inside an Android app package, decoding and loading a hidden second-stage payload only after installation. Once active, it hides itself from the device's recent apps view and can gain control over the device's interface if certain permissions are already enabled.

The second stage gives attackers a wide range of remote control capabilities, including running commands, transferring files, and creating hidden network tunnels. Most concerning is a built-in worm feature that scans networks for devices with Android Debug Bridge (a tool typically used by developers) left exposed. When found, the malware can automatically install itself onto these devices without needing a password, and in some cases modify system settings to embed itself more deeply.

Dark Atlas also found the malware includes checks designed to detect and avoid security researchers' analysis tools, suggesting its developers are actively trying to evade detection. The command-and-control server used to control infected devices was still active as of early September, according to the researchers.

Android malware mobile security remote access trojan

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.