ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain — Threadlinqs Intelligence
As of 2026-07-23, ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain is a high-severity campaign threat attributed to Cyber Av3ngers (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1659 · Severity: HIGH · Status: ACTIVE · Category: CAMPAIGN
Attribution: Cyber Av3ngers · Iran · DESTRUCTION
CISA, FBI, and EPA updated advisory AA26-097A (originally April 7, 2026; updated July 22, 2026) on Iranian-affiliated APT actors — linked to IRGC-CEC/CyberAv3ngers tradecraft — using leased
This threat bulletin (aggregated from The Hacker News' ThreatsDay roundup, published 2026-07-23) documents two converging campaigns.
**1) Iran-affiliated PLC intrusion campaign (CISA AA26-097A).** CISA, FBI, EPA, and government partners updated an advisory originally issued April 7, 2026, warning of ongoing exploitation of internet-connected operational technology by Iranian-affiliated APT actors whose tradecraft overlaps with IRGC Cyber-Electronic Command (IRGC-CEC) and the previously disclosed CyberAv3ngers persona (first publicized November 2023 for Unitronics PLC defacements). The July 22, 2026 update adds guidance for detecting malicious changes to reusable code modules — specifically malicious Add-On Instructions (AOIs) — within Rockwell Automation PLC programs. Actors used leased, third-party-hosted infrastructure and foreign-sourced IP addresses to reach misconfigured, internet-facing PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. Rather than exploiting a specific CVE, the actors abused legitimate vendor configuration software — Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation (TIA) Portal — to authenticate to exposed engineering ports, exfiltrate PLC project files, delete project logic, and manipulate data rendered on HMI/SCADA displays. At one victim site, attackers inserted override routines that disabled critical shutdown and alarm logic, and used Dropbear SSH for command-and-control persistence over port 22. Targeted OT protocol ports included 44818 and 2222 (Rockwell EtherNet/IP), 102 (Siemens S7comm), and 502 (Modbus TCP). CISA published 12 malicious source IP addresses with observed activity spanning September 2025 through July 2026. Impacted sectors are Water and Wastewater Systems (WWS), Energy, and Government Services and Facilities, with confirmed operational disruption and financial loss at affected sites. Attribution confidence is assessed MEDIUM by the authoring agencies, who note Iran-affiliated actors have historically used ransomware-gang personas as cover and that attribution to a specific unit remains difficult.
**2) OctagonPanel/Ward RAT 'BH Alert' Android spyware campaign.** Discovered July 17, 2026 by researchers at DreamGroup, this campaign exploits heightened public anxiety after Gulf-nation civil-defense sirens were activated in July 2026 following regional missile threats. Threat actors built a network of look-alike domains (playgoogle.alertbh[.]com, download.alert-bh[.]com, download.bh-security[.]com) cloning both the Google Play Store storefront and official Bahraini government portals, complete with fake install animations and ad-tracking pixels, to distribute a trojanized 'BH Alert' civil-defense siren app via smishing and social-media links. The malware uses a four-stage infection chain: Stage 0 ('Ematterassist') is an RC4-encrypted loader disguised as a font file (ZfChs.ttf) that injects hidden DEX code; Stage 1 (package com.kit.kitty) presents a social-engineering UI requesting invasive Android permissions and silently installs a secondary APK; Stage 2 ('Hvoicemanual') is a secondary RC4-encrypted shell that decrypts and launches the main payload; Stage 3 (package com.kisa.octagonpanel) is the OctagonPanel/Ward RAT itself, which abuses Android AccessibilityService (registered as WardAccessibilityService) to harvest lockscreen PIN/pattern input, intercept SMS and one-time passwords, exfiltrate contacts/call logs, capture screenshots, enumerate installed apps, render phishing overlays atop legitimate banking apps, execute arbitrary remote commands via an encrypted C2 channel, self-exclude from the recent-apps switcher, and deploy a fake VPN service to disrupt legitimate connectivity while preserving attacker C2. The campaign is assessed to primarily target Bahraini (and secondarily Kuwaiti) mobile users during a period of elevated civil-defense app adoption.
**Adjacen
Weaknesses (CWE)
CWE-284, CWE-306, CWE-250, CWE-923
Target sectors: waterwastewater, energy, government administration, criticalinfrastructure, finance, mobileusers, telecoms
Target regions: North America, Middle East, bahrain, kuwait, Gulf Cooperation Council
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, HIGH, threat intelligence, cybersecurity, T0819, T0886, T0807, T0821, T0843, T0889, T0848, T0861, T0868, T0869