Threats Tagged 'tc9'
View all threats tagged with 'tc9'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tc9'
Click on any threat for detailed analysis and mitigation recommendations
Inside a Packed Android RAT Loader 0 Hagaseca is an Android malware cluster linked to exposed Android Debug Bridge (ADB) services, focusing on the THost9 RAT loader variant. The malware conceals executable code within an APK that loads tc9.dex, a stage providing shell access, file transfer, and ADB propagation capabilities. Public incidents connect THost4 and THost9 to exposed Android and Redroid systems from October 2024 through 2026. The loader uses XOR and gzip packing, establishes persistence through foreground services, exploits accessibility features for device control, and downloads additional stages from test.hagaseca.com. The tc9.dex stage implements remote administration, discovers ADB endpoints via mDNS, scans entire /16 networks, authenticates with prepared keys, and installs itself on vulnerable systems. The malware exhibits worm-like behavior, spreading opportunistically through unsecured ADB services exposed to the internet, particularly affecting Redroid container deployments and devices with public ADB over Wi-Fi. Join the discussion | AlienVault OTX General | 09/08/2026, 16:59:09 UTC Added: 09/09/2026, 08:52:20 UTC |
Showing 1 to 1 of 1 result