Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data — Threadlinqs Intelligence
As of 2026-08-03, Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1832 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
A four-stage Android RAT tracked as Octagon/OctagonPanel, built on a component set researchers call the "Ward" framework, impersonates Bahrain's official BH Alert emergency-notification app (and MyGov
In mid-July 2026, amid heightened Gulf-region tension and civil-defense siren activations in Bahrain and Kuwait following regional missile threats, Dream Research Lab (an Abu Dhabi-based sovereign-AI/national cyberdefense firm) first identified (2026-07-17) a malicious Android campaign spoofing Bahrain's official "BH Alert" emergency-alert application, and published its original technical research blog disclosing the campaign publicly on 2026-07-20. The trojanized app was distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government portals (Civil Defence, Interior Ministry, and Information & eGovernment Authority branding) — complete with fake install-progress animations and ad-tracking pixels to look legitimate — as well as via smishing links shared on social media and messaging platforms. Fabricated listings claimed over 100,000 downloads with fake reviews to appear legitimate. Dream noted the campaign relies on social engineering and abuse of legitimate Android permissions, delivered under a public-safety brand at the exact moment users are primed to install it; the same vendor had previously documented a similar trojanized Israeli "Red Alert" civil-defense siren app (approx. March 2026) used for silent surveillance data collection, indicating this public-safety-brand playbook is a repeat tactic rather than a one-off.
The malware runs a four-stage infection chain: a package named 'Ematterassist' acts as an RC4-encrypted stage-0 loader hidden inside a font asset (ZfChs.ttf), which decrypts to ZfChs.dex and is loaded at runtime via DexClassLoader; 'com.kit.kitty' presents the stage-1 social-engineering UI that walks the victim through granting permissions under the guise of enabling emergency alerts; 'Hvoicemanual' is an RC4-encrypted stage-2 shell that decrypts the main payload; and 'com.kisa.octagonpanel' is the stage-3 payload — the OctagonPanel RAT itself, built on the "Ward" framework (evidenced by the malicious 'WardAccessibilityService' component). A dynamically generated child JAR (ZGdSEl.jar, staged under com.kisa.octagonpanel's app_walk directory) can be produced/installed at runtime, and the AndroidManifest declares classes that do not exist at install time, only materializing after in-memory/streamed installation via the PackageInstaller API — a design intended to defeat static analysis.
Once installed, the malware requests VPN-service permission (to intercept and filter device traffic while maintaining its own outbound channel), Accessibility Service (to monitor lock-screen unlock events and capture PINs/passwords/patterns, and to run phishing overlays on top of legitimate banking apps), and Install-Unknown-Apps (to sideload the child APK/JAR). Harvested lock-screen credentials are written locally to captured_passwords.json; SMS messages (including one-time passwords), contacts, and call logs are collected; screenshots and UI state are captured; and stolen data is staged in a local SQLite database (octagon_ward.db) before being transmitted to a hardcoded C2 server at 209.99.184.50 on TCP port 4444, with the C2 configuration itself persisted client-side in a SharedPreferences file named octagon.xml. Persistence is maintained through boot receivers, foreground services, watchdog processes, and abuse of Android's AccountManager/SyncAdapter framework (a 'SyncHelper' class registers a fake 'OctagonPanel' account to trigger periodic ~30-minute wakeups).
Coverage rippled outward from Dream's 2026-07-20 blog through Dark Reading (2026-07-22), Bahraini outlets GDN Online and Gulf News (2026-07-22), Cyber Security News (2026-07-23), The Hacker News's ThreatsDay roundup (2026-07-23), and TeamWin/Mallory.ai (2026-07-24), before K7 Security Labs independently published its own deeper technical analysis on 2026-08-03, confirming the package names, hashes, C2 endpoint, and RC4/DexClassLoader loading chain. No CVE applies — this is a malicious trojanized application dis
Target sectors: government administration, finance
Target regions: Middle East, Gulf Cooperation Council (GCC), bahrain, kuwait
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1398, T1624, T1541, T1626, T1407, T1406, T1655, T1541, T1632