Researchers reported an Android malware campaign using a trojanized BH Alert application that impersonates Bahrain’s official civil defense emergency app to infect users and establish long-term device control. The malware, tracked as Octagon, uses a multi-stage infection chain with dynamically loaded encrypted DEX and JAR payloads, installs a secondary child APK, and abuses Android VPN and Accessibility services to expand surveillance and credential theft. Analysts said the malware can intercept device traffic, capture lock-screen credentials, and store stolen data locally while preserving command-and-control configuration and operational state in SharedPreferences.
The campaign was also linked to infrastructure and artifacts associated with the fake BH-Alert APK, including package identifiers, file hashes, BH-Alert-themed distribution URLs, and a command-and-control endpoint at 209.99.184.50:4444. Octagon was described as a modular and persistent Android threat that survives reboots through mechanisms including AccountManager, Sync Adapter abuse, watchdog-style services, and boot receivers, enabling resilient access to compromised devices and sustained monitoring of victims in Bahrain.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Published indicators tied the campaign to package names com.kit.kitty and com.kisa.octagonpanel, the C2 server 209.99.184.50:4444, and BH-Alert distribution URLs. A second reference separately listed the same infrastructure and package identifiers, reinforcing those indicators.
The malware registered a fake account named "OctagonPanel" and enabled periodic synchronization every 30 minutes to wake itself and survive on infected devices. It also preserved command-and-control and operational settings in SharedPreferences for continued control.
The malware requested VPN access to intercept and redirect device traffic and used Android Accessibility Service to capture lock-screen PINs, passwords, and unlock patterns. Captured credentials and other stolen data were stored locally for later command-and-control transmission.
The fake BH Alert app dynamically decrypted and loaded an additional DEX payload, then installed and launched a child APK, com.kisa.octagonpanel. The child component loaded a further JAR payload and expanded the malware's surveillance and credential-theft capabilities.
Researchers described an Android malware campaign that impersonated Bahrain's official BH Alert emergency application using a malicious APK named "BH-Alert.apk." The app was distributed through infrastructure including download.alertbh.info, bh-alert.com, and playgoogle.bh-alert.com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcelabs.k7computing.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.