Octagon is a multi-stage Android malware family used for account takeover and financial fraud. It is operated as a malware-as-a-service offering and is designed to turn infected Android devices into remotely controlled theft platforms focused on banking, cryptocurrency, and messaging applications. Campaigns attributed to Octagon have impersonated trusted mobile applications, including Bahrain-themed government emergency services, to socially engineer victims into sideloading malicious APKs and granting high-risk permissions.
Octagon uses a modular architecture that dynamically decrypts and loads additional DEX and JAR payloads at runtime, reducing its static footprint and allowing operators to update functionality without rebuilding the entire application. Observed infection chains include staged installation of a secondary child application that expands surveillance and credential-theft functions. The malware abuses Android Accessibility Service to inspect screen content, simulate taps and text entry, monitor lock-screen events, and capture PINs, passwords, unlock patterns, and other sensitive input. It also uses overlay-based phishing to place fake forms over legitimate applications in order to steal credentials and wallet recovery phrases.
A notable feature of Octagon is abuse of Android VPN functionality to intercept or redirect device traffic, facilitating theft of banking credentials and other sensitive information while selectively excluding some applications to reduce user suspicion. The malware has also been observed requesting SMS permissions and collecting or forwarding incoming messages, including one-time passcodes. Additional collection capabilities include screenshots, contacts, call records, targeted application data, and locally stored operational information used to support phishing and remote control.
Octagon maintains persistence through multiple Android mechanisms, including boot-time relaunch, paired watchdog-style background services, and abuse of AccountManager and Sync Adapter functionality through registration of a fake account and periodic synchronization. It stores configuration, stolen data, phishing templates, and queued command data locally, and communicates with operator infrastructure over encrypted channels. Operators manage infected devices through a control panel that supports real-time interaction, tailored overlays, application checks, and balance-focused fraud workflows.
Octagon has been associated with Russian-speaking cybercrime activity and has been marketed to enable credential theft, wallet compromise, and broader financial fraud. Its targeting has centered on Android users, with observed emphasis on victims in Bahrain as well as users of cryptocurrency wallets, exchanges, banking apps, and messaging services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The SyncHelper class as shown in Figure 14, abuses Android’s AccountManager and Sync Adapter framework by registering a fake account (OctagonPanel) and enabling periodic synchronization every 30 minutes.
The malware then installs a child application known as OctagonPanel and creates another code file at runtime.
The SyncHelper class as shown in Figure 14, abuses Android’s AccountManager and Sync Adapter framework by registering a fake account (OctagonPanel) and enabling periodic synchronization every 30 minutes.
The SyncHelper class as shown in Figure 14, abuses Android’s AccountManager and Sync Adapter framework by registering a fake account (OctagonPanel) and enabling periodic synchronization every 30 minutes.
The SyncHelper class as shown in Figure 14, abuses Android’s AccountManager and Sync Adapter framework by registering a fake account (OctagonPanel) and enabling periodic synchronization every 30 minutes.
The SyncHelper class as shown in Figure 14, abuses Android’s AccountManager and Sync Adapter framework by registering a fake account (OctagonPanel) and enabling periodic synchronization every 30 minutes.
Our analysis revealed that the malware extracts an encrypted payload (ZfChs.ttf) from the application’s assets directory, decrypts it using an RC4-based routine
Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.
Accessibility is meant to help people use phones, but here it records lock-screen PINs, passwords and patterns as they are entered.
The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.
The malware can steal device unlock details... Accessibility is meant to help people use phones, but here it records lock-screen PINs, passwords and patterns as they are entered.
The database stores targeted application lists, malware configuration, phishing templates, intercepted SMS messages, and pending responses awaiting transmission to the C2 server.
Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.
Accessibility is meant to help people use phones, but here it records lock-screen PINs, passwords and patterns as they are entered.
The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.
Researchers recovered three related APK samples that share a client design, encrypted control connection, accessibility setup, and overlay assets.
Upon activation, it establishes a malicious VPN tunnel to intercept and redirect all device traffic, facilitating the exfiltration of banking credentials and other sensitive information.
The malware performs an in-memory installation of the embedded payload (payload.base) by streaming it from the application’s assets into a PackageInstaller session, without first creating a standalone APK file on disk
The Android implant connects to a Windows-based control panel. Buyers can check apps and balances, push a tailored overlay, and steer the screen in real time.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware sold as a service that abuses accessibility features to read screen content, inspect app interfaces, deploy overlay phishing forms, capture credentials and wallet recovery phrases, collect screenshots, steal SMS one-time codes, and enable remote control of the infected device for fraud and account takeover.
Android malware masquerading as Bahrain’s BH Alert emergency app. It uses a staged installation flow, decrypts hidden code at runtime, installs a child component, persists across reboots via boot receivers and paired watchdog services, abuses Accessibility to capture PINs/passwords/patterns, requests a rogue VPN to intercept or redirect traffic, steals SMS, contacts, call logs, screenshots, banking information and other device data, and overlays phishing pages on targeted apps.
Multi-stage Android malware that impersonates Bahrain's BH Alert app, dynamically loads encrypted DEX/JAR payloads, abuses VPN and Accessibility services, installs a child APK, captures lock-screen credentials, intercepts SMS and other sensitive data, stores stolen data locally, and communicates with a C2 server for long-term device control.
A multi-stage Android malware family that impersonates Bahrain's BH Alert app, dynamically loads encrypted DEX/JAR payloads, abuses VPN and Accessibility services, installs a child APK, captures lock-screen credentials, intercepts SMS and other sensitive data, stores stolen data locally, and communicates with a configurable C2 server for long-term device control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.