# "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform

> A malicious Android app named "BH Alert" impersonates Bahrain's Civil Defence, Ministry of Interior, and Information & eGovernment Authority (with false UNDRR branding) to trick residents into sideloading a four-stage surveillance platform. The campaign, discovered by Dream Research Labs on July 17, 2026, exploits heightened public demand for emergency-alert apps during GCC civil-defense siren activations tied to Iranian missile activity, delivering the OctagonPanel RAT and Ward C2 framework via fake Google Play storefronts.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1636
- **ID:** TL-2026-1636
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Researchers at Dream Research Labs, a cybersecurity vendor focused on national defense and critical infrastructure, disclosed on July 17-20, 2026 a malicious Android application called "BH Alert" that poses as an official Bahraini civil-defense emergency siren/alert application. The app is distributed through a network of look-alike domains that clone both the Google Play Store storefront UI and official Bahraini government websites, presenting bilingual (English/Arabic) content, a fabricated government publisher label, fake install animations, more than 100,000 fabricated download counts, and fake user reviews to establish false legitimacy. The listing further falsely claims to be 'Verified by Play Protect' and references the United Nations Office for Disaster Risk Reduction (UNDRR) to add unearned credibility.

When a victim clicks install, a timer-driven download delivers an approximately 20MB APK hosted outside the legitimate Google Play Store. The install flow is framed as a mandatory 'siren alert' setup wizard that walks the user through a sequence of dangerous Android permission grants presented as required for emergency alerting, but which in reality serve two purposes: (1) enabling installation of a secondary payload package, and (2) securing the device privileges needed for persistent, operator-controlled surveillance. The permission chain specifically abuses install-from-unknown-sources, SMS read/receive, contacts read, Accessibility Service, and draw-over-other-apps (SYSTEM_ALERT_WINDOW/overlay) grants.

The infection chain operates in four stages: Stage 1 injects the BH Alert installer DEX file; Stage 2 installs and launches the initial payload; Stage 3 injects the OctagonPanel malware component together with the 'Ward' framework (used for command-and-control, live surveillance, and remote operations) via the payload package identified as com.kisa.octagonpanel; Stage 4 establishes and maintains a persistent, operator-controlled surveillance session with reboot survival.

OctagonPanel functions as the primary remote access trojan (RAT) and is capable of: intercepting SMS messages including one-time passcodes (OTPs) used for two-factor/multi-factor authentication; harvesting the device contact list; capturing lockscreen credentials; taking screenshots; conducting accessibility-service-based surveillance of on-screen activity; stealing stored and entered credentials; injecting phishing overlays on top of legitimate banking applications to capture banking credentials; and giving the remote operator full interactive control of the compromised device. Because OTP interception undermines SMS-based MFA, researchers note that a single compromised personal or employee device could be leveraged to bypass MFA protections and pivot into corporate application access — elevating the threat beyond individual financial fraud into a potential enterprise initial-access vector (e.g., BYOD scenarios).

The campaign's timing directly exploits regional crisis conditions: throughout July 2026, GCC states including Bahrain and Kuwait have been actively sounding civil-defense sirens and issuing public-safety guidance to residents in response to Iranian missile activity in the region. During active air-defense events, legitimate official emergency-alert applications see sharp spikes in install demand, and the threat actors behind BH Alert deliberately timed and branded the campaign to intercept that demand — a form of crisis/disaster-themed social engineering targeting a civilian population under genuine physical-safety stress. Bahraini authorities (reported via GDN, Bahrain's Gulf Daily News) have since issued public warnings urging residents to install official alert apps only via verified government websites and verified social-media accounts, to check for URL misspellings/redirects, and to confirm any Play Store listing resolves to the legitimate play.google.com domain. McAfee Labs and TechNadu independently syndicated coverage of the campaign, reinforcing the financial-fraud angle (personal-data theft feeding downstream banking fraud) alongside the surveillance/espionage-adjacent capability set.

As of publication, no CVE is associated with this threat (it is a pure social-engineering/malware-installation campaign, not a software vulnerability exploit), and no specific named threat-actor group, C2 domain, or malware sample hash has been publicly confirmed in available open-source reporting; attribution remains unattributed/unknown in public sources at this time.

## MITRE ATT&CK

- T1660 Phishing
- T1456 Drive-By Compromise
- T1476 Deliver Malicious App via Other Means
- T1461 Lockscreen Bypass
- T1204 User Execution
- T1541 Foreground Persistence
- T1624 Event Triggered Execution
- T1398 Boot or Logon Initialization Scripts
- T1444 Masquerade as Legitimate Application
- T1407 Download New Code at Runtime
- T1628.001 Suppress Application Icon
- T1632.001 Code Signing Policy Modification
- T1417 Input Capture
- T1417.002 GUI Input Capture
- T1517 Access Notifications
- T1418 Software Discovery
- T1513 Screen Capture
- T1636.004 SMS Messages
- T1636.003 Contact List
- T1533 Data from Local System
- T1437 Application Layer Protocol
- T1219 Remote Access Tools
- T1646 Exfiltration Over C2 Channel
- T1582 SMS Control
- T1629.002 Device Lockout
- T1643 Generate Traffic from Victim

## Sources

- [Fake Bahrain Alert App Deploys Android Surveillance Malware](https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware)
- [Bahrain News: Fake alert app warning](https://www.gdnonline.com/Details/1401276/Fake-alert-app-warning)
- [Fake Android Apps Phish Sensitive Details in Bahrain](https://www.technadu.com/android-malware-poses-as-government-app-to-phish-sensitive-details-bahrain/529538/)
- [Fake Bahrain Government Android App Steals Personal Data Used for Financial Fraud](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-bahrain-government-android-app-steals-personal-data-used-for-financial-fraud/)
- [2026 Iranian strikes on Bahrain](https://en.wikipedia.org/wiki/2026_Iranian_strikes_on_Bahrain)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1636
