Back to Intelligence

Redis Rogue-Replication Miner, Hagaseca Android RAT Loader, DarkSword/Coruna iOS Exploit Platform: OTX Detection Pack

SA
Security Arsenal Team
October 8, 2026
8 min read

Threat Summary

These three TLP:WHITE pulses collectively show a mature criminal and exploitation ecosystem converging on exposed services rather than sophisticated initial access. The Redis operation used unauthenticated Redis and rogue replication to write cron jobs, deploy XMRig and Meterpreter, and scale to 3,562 confirmed compromised servers from 12,966 targets. The operator exposed their own toolkit at 188.245.99.156, including 147 files, Python exploit source, campaign logs and Windows registry hives. Hagaseca/THost9 targets exposed Android Debug Bridge and Redroid systems, loading tc9.dex to provide shell access, file transfer, accessibility abuse and worm-like ADB propagation. DarkSword/Coruna is more commercially alarming: five open directories exposed an iOS exploitation-as-a-service platform using CVE-2025-31200, CVE-2025-24201 and CVE-2026-31001 references, with tooling branded GHOSTBLADE, GHOSTKNIFE and GHOSTSABER to extract BIP39 recovery phrases across 18 wallet applications. Recovered server artifacts included 11 victim recovery phrases and 179 device loot records, proving hands-on-keyboard theft rather than theoretical capability.

The shared objective is monetization: compute theft via Monero mining, mobile device control and resale, and direct cryptocurrency wallet draining. The shared root cause is internet-facing debug, database and exploitation infrastructure with weak authentication, open directories and poor artifact hygiene.

Threat Actor / Malware Profile

Redis cryptomining botnet — distribution is opportunistic scanning for unauthenticated Redis, followed by rogue replication or module-style abuse to inject cron persistence. Payload behavior centers on XMRig for CPU mining and Meterpreter for interactive control. Persistence is cron-injection; host artifacts may include modified crontabs, /etc/cron.d entries, downloaded miners, bash history, Redis dump files and registry hives when operators stage Windows tooling. C2 or tasking can blend with mining pools, Meterpreter sessions and domains such as ayakliborsa.net and socket.ayakliborsa.net. Anti-analysis is opportunistic but effective: packed Python exploit source, disposable infrastructure, logs left in exposed directories and reuse of legitimate Redis replication semantics.

Hagaseca / THost9 / THost4 / tc9 — distribution depends on exposed ADB services and Android or Redroid emulators reachable over TCP. The APK loader conceals executable logic and loads tc9.dex, which enables shell access, file transfer, accessibility abuse and ADB-to-ADB spread. C2 behavior includes beaconing to hagaseca.com and environment or IP enrichment such as api.ipapi.is. Persistence is weak by design but propagation compensates: once one emulator or test device is compromised, accessible ADB peers are enumerated and pushed payloads. Anti-analysis includes packed APKs, DEX stage separation, tc9.dex naming, accessibility permission abuse and emulator-aware execution.

DarkSword/Coruna with GHOST tooling — distribution is exploitation-as-a-service against iOS devices, likely via exploit delivery pages and operator-managed staging. Payload behavior targets wallet apps and extracts BIP39 recovery phrases, device loot and clipboard or keystore-adjacent secrets. C2 and staging were exposed through open directories on hosts including 185.189.45.40, 154.18.187.160, 14.128.47.81, 166.88.95.90 and 112.213.108.85, with escofiringbijou.com among observed domains. Persistence is less relevant than speed: exploit, loot phrase, sign transactions, move funds. Anti-analysis includes commercial packaging, branded tool names, segmented servers and rapid infrastructure rotation.

IOC Analysis

The indicator set mixes file hashes, domains, hostnames, URLs, IPv4 staging servers and CVE references. FileHash-MD5/SHA1/SHA256 values such as f90c8b1dcd374d4f552744ee1765583d, 420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a and the Hagaseca hashes should be pushed to EDR blocklists, sandbox detonation queues and retro-hunts. Domains and hostnames such as ayakliborsa.net, socket.ayakliborsa.net, hagaseca.com and escofiringbijou.com should be blocked at DNS, proxy and TLS inspection layers with alert-on-resolution and alert-on-failed-lookup for malware already present. IPv4 indicators are highest value for egress firewall, NetFlow, Zeek/Suricata and cloud security group retro-hunting because open directories and exploit staging often reuse hosting. CVEs are not blockable indicators; use them for asset attack-surface correlation, especially iOS fleet exposure, mobile browser/WebKit patch posture and exploit kit telemetry.

SOC operationalization: normalize indicators into STIX/TAXII or your TIP, set expiry by type, enrich with passive DNS and sandbox verdicts, and prioritize SHA256 over MD5/SHA1 where collisions matter. Tooling: YARA for hash and filename sweeps, Suricata/Zeek for DNS and IP hits, Sigma for host behavior, KQL for fleet retro-hunt, MobileThreatDefense for Android/iOS posture, and blockchain investigation workflows for any confirmed BIP39 exposure.

Detection Engineering

YAML
---
title: Redis Rogue Replication Cron Injection
date: 2026/10/08
status: experimental
description: Detects unauthenticated Redis abuse using rogue replication or slaveof/replicaof followed by cron persistence and miner download behavior referenced in OTX Redis botnet pulse.
logsource:
  category: process_creation
  product: linux
detection:
  selection_replication:
    CommandLine|contains:
      - 'redis-cli'
      - 'REPLICAOF'
      - 'SLAVEOF'
      - 'replicaof'
      - 'slaveof'
  selection_cron_persist:
    CommandLine|contains:
      - '/etc/cron'
      - 'crontab'
      - 'cron.d'
      - 'systemd-run'
  selection_miner:
    CommandLine|contains:
      - 'xmrig'
      - 'monero'
      - 'stratum+tcp'
      - 'curl http'
      - 'wget http'
  condition: selection_replication or (selection_cron_persist and selection_miner)
falsepositives:
  - Legitimate Redis cluster administration
  - Package or configuration management using crontab
level: high
tags:
  - attack.persistence
  - attack.t1053
  - attack.t1496
  - attack.t1071
references:
  - https://hunt.io/blog/redis-cryptomining-botnet-3562-servers
---
title: OTX Pulse Infrastructure Egress To Criminal Staging
date: 2026/10/08
status: experimental
description: Detects DNS, proxy or network egress to domains, hostnames and IPv4 addresses exposed in Redis miner, Hagaseca Android RAT and DarkSword/Coruna open-directory pulses.
logsource:
  category: network_connection
detection:
  selection_dns:
    DestinationHostname|contains:
      - 'ayakliborsa.net'
      - 'socket.ayakliborsa.net'
      - 'hagaseca.com'
      - 'escofiringbijou.com'
      - 'api.ipapi.is'
  selection_ip:
    DestinationIp:
      - '188.245.99.156'
      - '185.189.45.40'
      - '154.18.187.160'
      - '14.128.47.81'
      - '166.88.95.90'
      - '112.213.108.85'
  condition: selection_dns or selection_ip
falsepositives:
  - Threat research or sandbox detonation
  - CTI enrichment to ipapi.is from controlled tooling
level: high
tags:
  - attack.command_and_control
  - attack.exfiltration
  - attack.t1071
  - attack.t1041
references:
  - https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
  - https://censys.com/blog/darksword-coruna-open-directory-finding-report/
---
title: Hagaseca Android ADB Propagation And DEX Staging
date: 2026/10/08
status: experimental
description: Detects exposed ADB enablement, ADB connect/push behavior, tc9.dex staging and accessibility abuse consistent with Hagaseca THost9 loader activity.
logsource:
  category: process_creation
detection:
  selection_adb:
    CommandLine|contains:
      - 'adb connect'
      - 'adb push'
      - 'adb shell'
      - 'adb devices'
      - '5555'
  selection_stage:
    CommandLine|contains:
      - 'tc9.dex'
      - 'THost9'
      - 'THost4'
      - 'hagaseca'
      - 'pm install'
  selection_accessibility:
    CommandLine|contains:
      - 'accessibility'
      - 'settings put secure enabled_accessibility_services'
      - 'input tap'
      - 'uiautomator'
  condition: selection_adb and (selection_stage or selection_accessibility)
falsepositives:
  - Mobile application QA labs
  - Managed Redroid or emulator farms
level: medium
tags:
  - attack.lateral_movement
  - attack.t1021
  - attack.t1546
  - attack.t1059
references:
  - https://darkatlas.io/blog/hagaseca-inside-a-packed-android-rat-loader
KQL — Microsoft Sentinel / Defender
let BadIP = dynamic(["188.245.99.156","185.189.45.40","154.18.187.160","14.128.47.81","166.88.95.90","112.213.108.85"]);
let BadDomain = dynamic(["ayakliborsa.net","socket.ayakliborsa.net","hagaseca.com","escofiringbijou.com","api.ipapi.is"]);
union isfuzzy=true
(
    DeviceNetworkEvents
    | where TimeGenerated > ago(14d)
    | where RemoteIP in (BadIP) or RemoteUrl has_any (BadDomain)
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort, ActionType
),
(
    DeviceProcessEvents
    | where TimeGenerated > ago(14d)
    | where ProcessCommandLine has_any ("redis-cli","REPLICAOF","SLAVEOF","replicaof","slaveof","xmrig","stratum+tcp","meterpreter","crontab","/etc/cron","adb connect","adb push","tc9.dex","THost9","THost4","hagaseca","enabled_accessibility_services")
       or FileName in~ ("xmrig","redis-cli","adb")
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, FolderPath, InitiatingProcessFileName, SHA256
),
(
    DeviceFileEvents
    | where TimeGenerated > ago(14d)
    | where SHA256 in~ ("420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a","54d4ee85175a249dcb576716edf491d09fa05dfdfc492ff710a0cb711f9a35ab")
       or MD5 in~ ("f90c8b1dcd374d4f552744ee1765583d","bdca0eb738faaccb5b992d0f393b9d9f","24f344e174546e780332d573d5a27c43","dfd9c7dee4f4a16d636917de35a510b7")
       or FileName has_any ("tc9.dex","xmrig","redis","dump.rdb")
    | project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, MD5, ActionType
)
| order by TimeGenerated desc
Bash / Shell
#!/usr/bin/env bash
set -euo pipefail
BAD_IPS='188.245.99.156|185.189.45.40|154.18.187.160|14.128.47.81|166.88.95.90|112.213.108.85'
BAD_DOM='ayakliborsa.net|socket.ayakliborsa.net|hagaseca.com|escofiringbijou.com|api.ipapi.is'
BAD_HASH='f90c8b1dcd374d4f552744ee1765583d|420c7850e09b7c2b9e39e2a93e204e3c56bcf08a685ff1daa986e3c348da5d2a|bdca0eb738faaccb5b992d0f393b9d9f|24f344e174546e780332d573d5a27c43|dfd9c7dee4f4a16d636917de35a510b7|54d4ee85175a249dcb576716edf491d09fa05dfdfc492ff710a0cb711f9a35ab'
echo '[+] Network egress hits'; ss -antp 2>/dev/null | grep -E "$BAD_IPS" || true; netstat -antp 2>/dev/null | grep -E "$BAD_IPS" || true
echo '[+] DNS cache and resolver logs'; grep -R -E "$BAD_DOM" /var/log/syslog /var/log/messages /var/log/dns* 2>/dev/null | tail -n 200 || true
echo '[+] Cron persistence'; grep -R -E 'xmrig|monero|stratum\+tcp|redis-cli|REPLICAOF|SLAVEOF|ayakliborsa|meterpreter' /var/spool/cron /etc/cron.d /etc/crontab /etc/cron.daily /etc/cron.hourly 2>/dev/null || true
echo '[+] Redis exposure and rogue replication'; if command -v redis-cli >/dev/null 2>&1; then redis-cli -h 127.0.0.1 INFO replication 2>/dev/null | egrep 'role|master_host|master_port|slave' || true; fi; grep -R -E 'bind 0.0.0.0|protected-mode no|requirepass' /etc/redis /usr/local/etc/redis 2>/dev/null || true
echo '[+] Miner and RAT artifacts'; find /tmp /var/tmp /dev/shm /opt /srv /home -maxdepth 4 -type f \( -iname 'xmrig*' -o -iname '*tc9.dex*' -o -iname '*THost*' -o -iname '*hagaseca*' -o -iname 'config.json' \) -printf '%p %s bytes\n' 2>/dev/null | head -n 300 || true
echo '[+] Hash sweep priority paths'; find /tmp /var/tmp /dev/shm /opt /srv -maxdepth 4 -type f -size +20k -print0 2>/dev/null | xargs -0 -r sha256sum 2>/dev/null | grep -E "$BAD_HASH" || true
echo '[+] Android or Redroid ADB surface'; if command -v adb >/dev/null 2>&1; then adb devices 2>/dev/null || true; fi; ss -lnt 2>/dev/null | grep ':5555' || true
echo '[+] Recent wallet-theft adjacent strings on mobile build servers'; grep -R -E 'BIP39|recovery phrase|GHOSTBLADE|GHOSTKNIFE|GHOSTSABER|DarkSword|Coruna|escofiringbijou' /srv /opt /var/www /home 2>/dev/null | tail -n 200 || true

Response Priorities

Immediate: block listed IPv4s, domains and hostnames at DNS, proxy, egress firewall and EDR; quarantine hosts with SHA256/MD5 hits; isolate Redis servers bound to 0.0.0.0 or without protected-mode/auth; disable exposed ADB TCP 5555 on Android, Redroid and CI emulator farms; snapshot volatile memory and cron before remediation.

24h: treat any host that contacted DarkSword/Coruna infrastructure or handled BIP39 material as credential-compromised; force wallet key rotation where feasible, notify fraud and legal, review transaction-signing hosts, reset secrets on mobile build servers, verify developer and CI identities, and search for phrase exfiltration, clipboard capture and unexpected outbound TLS.

1 week: remove internet-exposed Redis or place behind VPN with TLS/auth; segment emulator farms and prohibit adb over TCP; enforce MDM/MTD policies blocking accessibility abuse and unknown sources; patch iOS fleet and WebKit components against listed CVEs; add detections for cron writes after Redis replication, ADB fan-out, DEX sideloading and open-directory exploit staging; create an attack-surface rule for exposed debug services and cryptocurrency-wallet developer endpoints.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.