Researchers reported that Octagon, an Android malware-as-a-service tool, is being used to hijack banking and cryptocurrency accounts by abusing Android accessibility services, overlay screens, and remote-control features. Identified by iVerify in June 2026, the malware was advertised on a Russian-language cybercrime forum by a seller using the handle AndroidKitKat for $1,400 per month. Octagon can steal credentials, wallet recovery phrases, screenshots, PINs, passwords, and SMS one-time codes, giving operators the ability to bypass multi-factor authentication and take over financial and messaging accounts.
Observed activity links Octagon to Android packages including com.kisa.octagonpanel, a Windows-based operator panel, and infrastructure that includes config.json, TCP port 4444, suspicious delivery or control URLs, and multiple IP addresses and file hashes. Researchers also tied the malware to themed APK lures, including a Lifted Dreams build and a Bahrain-themed campaign that used fake government and Google Play pages with a four-stage APK infection chain. The operation primarily targets wallets, exchanges, banking apps, and messaging platforms, with impersonation templates seen for Trust Wallet, Binance, and MEXC, while relying on sideloading and user-approved accessibility permissions to evade user suspicion and operate despite Play Protect showing no harmful apps.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
In June 2026, iVerify identified the Octagon Android malware and linked it to related APK samples sharing the package name com.kisa.octagonpanel, a default C2 key, and encrypted control traffic over TCP port 4444. Researchers also connected the malware to Lifted Dreams-themed and Bahrain-themed lures used to steal credentials, wallet phrases, and SMS one-time codes.
A Russian-speaking seller using the handle AndroidKitKat advertised the Octagon Android malware-as-a-service offering on a Russian-language cybercrime forum for $1,400 per month. The malware was positioned as a tool for account takeover and financial fraud.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.