ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain

ThreatsDay Bulletin (TL-2026-1659), also tracked as ThreatsDay Bulletin 2026-07-23, is a high-severity campaign, first published 2026-07-23. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Rockwell Automation Allen-Bradley PLCs / Studio 5000 Logix, maps to 34 MITRE ATT&CK techniques (T0807, T0813, T0819), and is covered by 9 detection rules and 34 indicators of compromise.

Key facts for TL-2026-1659

Threat ID
TL-2026-1659
Also known as
ThreatsDay Bulletin 2026-07-23, AA26-097A Update, BH Alert Campaign
Severity
HIGH
Status
ACTIVE
Category
CAMPAIGN
First published
2026-07-23
Last reviewed
2026-07-23
Attribution
Cyber Av3ngers
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
waterwastewater, energy, government administration, criticalinfrastructure, finance, mobileusers, telecoms
Target regions
North America, Middle East, bahrain, kuwait, Gulf Cooperation Council
Detection rules
9
Indicators of compromise
34

Malware and tooling in ThreatsDay Bulletin

Malware and tooling: Hvoicemanual, MarkiRAT - S0652, OctagonPanel, SectopRAT, Dropbear SSH, Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, Siemens TIA Portal

CISA, FBI, and EPA updated advisory AA26-097A (originally April 7, 2026; updated July 22, 2026) on Iranian-affiliated APT actors — linked to IRGC-CEC/CyberAv3ngers tradecraft — using leased infrastructure and legitimate vendor engineering software (Studio 5000 Logix Designer, EcoStruxure Control Expert, TIA Portal) to compromise internet-exposed Rockwell/Allen-Bradley, Schneider Electric, and Siemens PLCs across Water/Wastewater, Energy, and Government Services sectors, inserting malicious Add-On Instructions and disabling shutdown/alarm logic. Separately, a four-stage OctagonPanel/Ward RAT Android spyware platform is distributed via look-alike domains cloning Google Play and official Bahraini government sites under the guise of a 'BH Alert' civil-defense siren app, harvesting lockscreen credentials, intercepting SMS/OTP, running banking overlays, and granting full remote device control.

How ThreatsDay Bulletin works

This threat bulletin (aggregated from The Hacker News' ThreatsDay roundup, published 2026-07-23) documents two converging campaigns.

**1) Iran-affiliated PLC intrusion campaign (CISA AA26-097A).** CISA, FBI, EPA, and government partners updated an advisory originally issued April 7, 2026, warning of ongoing exploitation of internet-connected operational technology by Iranian-affiliated APT actors whose tradecraft overlaps with IRGC Cyber-Electronic Command (IRGC-CEC) and the previously disclosed CyberAv3ngers persona (first publicized November 2023 for Unitronics PLC defacements). The July 22, 2026 update adds guidance for detecting malicious changes to reusable code modules — specifically malicious Add-On Instructions (AOIs) — within Rockwell Automation PLC programs. Actors used leased, third-party-hosted infrastructure and foreign-sourced IP addresses to reach misconfigured, internet-facing PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. Rather than exploiting a specific CVE, the actors abused legitimate vendor configuration software — Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation (TIA) Portal — to authenticate to exposed engineering ports, exfiltrate PLC project files, delete project logic, and manipulate data rendered on HMI/SCADA displays. At one victim site, attackers inserted override routines that disabled critical shutdown and alarm logic, and used Dropbear SSH for command-and-control persistence over port 22. Targeted OT protocol ports included 44818 and 2222 (Rockwell EtherNet/IP), 102 (Siemens S7comm), and 502 (Modbus TCP). CISA published 12 malicious source IP addresses with observed activity spanning September 2025 through July 2026. Impacted sectors are Water and Wastewater Systems (WWS), Energy, and Government Services and Facilities, with confirmed operational disruption and financial loss at affected sites. Attribution confidence is assessed MEDIUM by the authoring agencies, who note Iran-affiliated actors have historically used ransomware-gang personas as cover and that attribution to a specific unit remains difficult.

**2) OctagonPanel/Ward RAT 'BH Alert' Android spyware campaign.** Discovered July 17, 2026 by researchers at DreamGroup, this campaign exploits heightened public anxiety after Gulf-nation civil-defense sirens were activated in July 2026 following regional missile threats. Threat actors built a network of look-alike domains (playgoogle.alertbh[.]com, download.alert-bh[.]com, download.bh-security[.]com) cloning both the Google Play Store storefront and official Bahraini government portals, complete with fake install animations and ad-tracking pixels, to distribute a trojanized 'BH Alert' civil-defense siren app via smishing and social-media links. The malware uses a four-stage infection chain: Stage 0 ('Ematterassist') is an RC4-encrypted loader disguised as a font file (ZfChs.ttf) that injects hidden DEX code; Stage 1 (package com.kit.kitty) presents a social-engineering UI requesting invasive Android permissions and silently installs a secondary APK; Stage 2 ('Hvoicemanual') is a secondary RC4-encrypted shell that decrypts and launches the main payload; Stage 3 (package com.kisa.octagonpanel) is the OctagonPanel/Ward RAT itself, which abuses Android AccessibilityService (registered as WardAccessibilityService) to harvest lockscreen PIN/pattern input, intercept SMS and one-time passwords, exfiltrate contacts/call logs, capture screenshots, enumerate installed apps, render phishing overlays atop legitimate banking apps, execute arbitrary remote commands via an encrypted C2 channel, self-exclude from the recent-apps switcher, and deploy a fake VPN service to disrupt legitimate connectivity while preserving attacker C2. The campaign is assessed to primarily target Bahraini (and secondarily Kuwaiti) mobile users during a period of elevated civil-defense app adoption.

**Adjacent items referenced in the same bulletin (lower-confidence, included for tag/technique coverage only, not separately scored):** a GitHub pull-request prompt-injection technique ('GhostCommit') hiding malicious LLM-reviewer instructions inside PNG image bytes to exfiltrate repository secrets; an Iran-nexus group tracked as TAG-182 distributing MarkiRAT via fake VPN/download-tool Android apps targeting the Iranian diaspora, sharing tradecraft with previously reported Ferocious Kitten activity; a TrickBot variant adding DNS-tunneling C2 (encrypted DNS query packets used to carry command traffic) for evasion; and a malvertising campaign ('FakeAgent') redirecting victims to spoofed Claude Artifacts pages serving a trojanized 'ClaudeDesktop.exe' that deploys SectopRAT, affecting at least 29 organizations July 21-22, 2026.

MITRE ATT&CK techniques used in TL-2026-1659

Execution

T0807 Command-Line Interface; T0821 Modify Controller Tasking

Impact

T0813 Denial of Control; T0837 Loss of Protection; T1582 SMS Control

initial-access

T0819 Exploit Public-Facing Application; T0848 Rogue Master; T0886 Remote Services; T1660 Phishing

Impair Process Control

T0836 Modify Parameter

lateral-movement

T0843 Program Download

Collection

T0861 Point & Tag Identification; T0868 Detect Operating Mode; T1513 Screen Capture; T1636 Protected User Data; T1636.003 Contact List; T1636.004 SMS Messages

command-and-control

T0869 Standard Application Layer Protocol; T0885 Commonly Used Port; T1437 Application Layer Protocol; T1663 Remote Access Software

execution

T0875 Change Program State

Inhibit Response Function

T0878 Alarm Suppression

Persistence

T0889 Modify Program; T1541 Foreground Persistence

defense-evasion

T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1629.002 Device Lockout

collection

T1417 Input Capture; T1638 Adversary-in-the-Middle

credential-access

T1417.002 GUI Input Capture

Discovery

T1418 Software Discovery

impact

T1471 Data Encrypted for Impact

evasion

T1692.002 Reporting Message

Affected products and versions in ThreatsDay Bulletin

  • Rockwell Automation — Allen-Bradley PLCs / Studio 5000 Logix Designer-managed controllers
    Vulnerable versions: internet-exposed deployments, all firmware versions
    Fixed in: N/A - misconfiguration issue; mitigate via network isolation
  • Schneider Electric — PLCs managed via EcoStruxure Control Expert
    Vulnerable versions: internet-exposed deployments, all firmware versions
    Fixed in: N/A - misconfiguration issue; mitigate via network isolation
  • Siemens — Controllers managed via TIA Portal (S7 protocol)
    Vulnerable versions: internet-exposed deployments, all firmware versions
    Fixed in: N/A - misconfiguration issue; mitigate via network isolation
  • Unofficial / Malicious — 'BH Alert' trojanized Android application (com.kisa.octagonpanel and dropper chain)
    Vulnerable versions: all versions distributed via look-alike domains
    Fixed in: N/A - malicious app; only official Google Play / Bahraini government-verified listing is legitimate

Remediation for ThreatsDay Bulletin

Patches

  • No CVE-based patch applicable; this is a misconfiguration/exposure and legitimate-tool-abuse issue, not a software vulnerability

Immediate actions

  • Disconnect all PLCs and OT engineering interfaces from direct internet exposure
  • Block inbound traffic to OT ports 44818, 2222 (Rockwell EtherNet/IP), 102 (Siemens S7comm), and 502 (Modbus TCP) at the perimeter
  • Block the 12 published malicious source IP addresses at network egress/ingress
  • Uninstall any 'BH Alert' APK not obtained from the official Google Play Store listing; scan devices for com.kisa.octagonpanel, com.kit.kitty, WardAccessibilityService
  • Revoke and rotate credentials on any device that had the fake BH Alert app installed, prioritizing banking and SMS/OTP-linked accounts

Workarounds

  • Set Rockwell/Allen-Bradley controller key switch to a protected/RUN-only mode to block remote program uploads
  • Restrict Studio 5000 Logix Designer, EcoStruxure Control Expert, and TIA Portal remote-connection capability to segmented management networks only
  • Monitor OT logs for overseas/foreign-sourced connection attempts to engineering ports

Longer-term hardening

  • Implement network segmentation between OT/ICS engineering workstations and the internet, using firewalls and secure remote-access gateways
  • Require VPN with strong multi-factor authentication for any remote PLC engineering access
  • Deploy integrity monitoring / code-review workflows for reusable PLC program modules and Add-On Instructions (AOIs)
  • Maintain offline, periodically-tested backups of PLC project files and configurations
  • Enable mobile threat defense (MTD) and restrict sideloading / unknown-sources installs on managed Android fleets
  • User awareness training on civil-defense/emergency-alert app spoofing during regional crisis events

Weaknesses (CWE) in ThreatsDay Bulletin

CWE-284, CWE-306, CWE-250, CWE-923

Timeline of ThreatsDay Bulletin

  • CyberAv3ngers persona first publicized for defacements of internet-exposed Unitronics PLCs, establishing baseline tradecraft later linked to this campaign
  • Earliest activity window for the 12 published malicious IP addresses targeting internet-exposed PLCs begins
  • CISA, FBI, EPA, and government partners publish original advisory AA26-097A on Iran-affiliated APT actors exploiting internet-connected OT/PLC devices
  • DreamGroup researchers discover the OctagonPanel/Ward RAT 'BH Alert' Android spyware campaign impersonating Bahrain's civil-defense siren app
  • Cybersecuritynews.com and Dark Reading publish technical analysis of the fake Bahrain Civil Defense Android RAT campaign
  • Bahraini news outlet GDN publishes a public warning about the fake alert app
  • FakeAgent malvertising campaign begins redirecting victims to spoofed Claude Artifacts pages delivering SectopRAT via trojanized ClaudeDesktop.exe, ultimately affecting at least 29 organizations
  • The Record, WaterISAC, ISSSource, GBHackers, and Rescana publish independent coverage/analysis of the updated CISA advisory
  • CISA updates AA26-097A with new guidance for detecting malicious Add-On Instruction (AOI) changes in Rockwell Automation PLC programs, plus the 12-IP IOC list covering the Sept 2025-Jul 2026 window
  • The Hacker News publishes the ThreatsDay Bulletin aggregating both the PLC advisory update and the OctagonPanel Android spyware campaign alongside adjacent threats (GhostCommit, MarkiRAT/TAG-182, TrickBot DNS tunneling, SectopRAT/FakeAgent)

Sources cited for ThreatsDay Bulletin

Threats related to ThreatsDay Bulletin

Detection coverage for TL-2026-1659

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1659 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats