As cited
Copy frozen at (site build).
threat intel
THost9 Android RAT Pairs Packed Loader With ADB Worm
THost9 is an Android remote access trojan (RAT) that employs a packed loader to conceal its payload and spreads via Android Debug Bridge (ADB) to other exposed Android devices and containers. The malware combines persistence mechanisms with worm-like propagation to establish footholds across interconnected systems.
Why it matters: Organizations running Android devices or containers with exposed ADB ports face direct infection risk and lateral movement; security teams should audit ADB exposure and implement network segmentation immediately.
- Source published
- First seen by Cybersecurity Tracker