Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign relies on a network of lookalike domains, and victims are tricked into downloading a malicious APK hosted outside official app stores; the initial infection vector is likely smishing or malicious links distributed via social media and messaging platforms.
Octagon adds a fake Android account, OctagonPanel, and schedules synchronization every 30 minutes. The routine can wake the malware periodically or on demand
The malware then installs a child application known as OctagonPanel and creates another code file at runtime.
The malware establishes persistence using foreground services, watchdog processes, and boot receivers to survive reboots and removal attempts.
Octagon adds a fake Android account, OctagonPanel, and schedules synchronization every 30 minutes. The routine can wake the malware periodically or on demand
Its services operate in the background, while watchdog processes monitor one another and restart a partner if it is stopped.
The malware establishes persistence using foreground services, watchdog processes, and boot receivers to survive reboots and removal attempts.
Octagon adds a fake Android account, OctagonPanel, and schedules synchronization every 30 minutes. The routine can wake the malware periodically or on demand
Its services operate in the background, while watchdog processes monitor one another and restart a partner if it is stopped.
The malware incorporates several anti-analysis controls: RC4-encrypted payloads hidden inside .ttf font files and .jar archives. Obfuscated code paths and junk logic to hinder reverse engineering.
This advisory is issued to raise awareness of a sophisticated Android malware campaign distributing a fake “BH Alert” app impersonating Bahrain's Civil Defense emergency alert application.
Once installed, the RAT abuses Android Accessibility Services and elevated system permissions to gain granular control over the device, including lockscreen theft | Once installed, the RAT abuses Android Accessibility Services and elevated system permissions to gain granular control over the device, including lockscreen theft, interception of SMS and OTP codes, phishing overlays mimicking banking apps
Phishing Overlays: Displaying fake login forms over banking apps, mirroring tactics seen in banking trojan campaigns.
The child app also gathers SMS messages, contacts, call records, screenshots and configuration data
Once installed, the RAT abuses Android Accessibility Services and elevated system permissions to gain granular control over the device, including lockscreen theft | Once installed, the RAT abuses Android Accessibility Services and elevated system permissions to gain granular control over the device, including lockscreen theft, interception of SMS and OTP codes, phishing overlays mimicking banking apps
Exercise remote administrative control of infected devices via encrypted C2 communication
The malware establishes persistence using foreground services, watchdog processes, and boot receivers, and notably deploys a fake VPN service that disrupts normal device connectivity for legitimate apps while keeping the attacker's own communication channel functional.
Stage 1 ( com.kit.kitty ): Social engineering interface requests permissions and installs a secondary APK payload.
OctagonPanel is the primary RAT, capable of intercepting SMSs, harvesting contacts, capturing screenshots, conducting accessibility-based surveillance, stealing credentials, adding banking app phishing overlays, controlling remote devices, and maintaining persistence after reboot.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage Android remote access trojan delivered via a fake Bahrain Civil Defense 'BH Alert' app. It steals lockscreen PINs, OTPs, SMS messages, banking credentials, captures screenshots, inventories device data, executes remote commands, abuses Accessibility Services, and maintains persistence through foreground services, watchdogs, and boot receivers.
Primary remote access trojan payload used by the BH Alert infection chain. It intercepts SMS, steals contacts and credentials, captures screenshots, performs accessibility-based surveillance, deploys banking overlays, remotely controls the device, and persists after reboot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.