Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware establishes persistence using foreground services, watchdog processes, and boot receivers to survive reboots and removal attempts.
The malware establishes persistence using foreground services, watchdog processes, and boot receivers to survive reboots and removal attempts.
The malware incorporates several anti-analysis controls: RC4-encrypted payloads hidden inside .ttf font files and .jar archives. Obfuscated code paths and junk logic to hinder reverse engineering.
A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application.
Data Exfiltration: Bulk reading contacts, call logs, and installed app inventories.
Key capabilities include: Lockscreen Theft: Harvesting PINs and pattern unlock inputs.
Remote Commands: Executing administrative tasks via encrypted C2 communication.
Stage 1 ( com.kit.kitty ): Social engineering interface requests permissions and installs a secondary APK payload.
OctagonPanel is the primary RAT, capable of intercepting SMSs, harvesting contacts, capturing screenshots, conducting accessibility-based surveillance, stealing credentials, adding banking app phishing overlays, controlling remote devices, and maintaining persistence after reboot.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage Android remote access trojan delivered via a fake Bahrain Civil Defense 'BH Alert' app. It steals lockscreen PINs, OTPs, SMS messages, banking credentials, captures screenshots, inventories device data, executes remote commands, abuses Accessibility Services, and maintains persistence through foreground services, watchdogs, and boot receivers.
Primary remote access trojan payload used by the BH Alert infection chain. It intercepts SMS, steals contacts and credentials, captures screenshots, performs accessibility-based surveillance, deploys banking overlays, remotely controls the device, and persists after reboot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.