Threat reportMalwareTL-2026-1832
Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
Octagon / OctagonPanel "Ward" Android RAT Impersonates (TL-2026-1832), also tracked as Octagon, is a high-severity malware campaign, first published 2026-08-03. It has no confirmed attribution, affects N/A (malicious third-party APK, not an official vendor product), maps to 21 MITRE ATT&CK techniques (T1398, T1406, T1407), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-1832
- Threat ID
- TL-2026-1832
- Also known as
- Octagon, OctagonPanel, Ward RAT, Ward framework, Fake BH Alert malware
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, finance
- Target regions
- Middle East, Gulf Cooperation Council (GCC), bahrain, kuwait
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Octagon / OctagonPanel "Ward" Android RAT Impersonates
Malware and tooling: Octagon, OctagonPanel, Ward
How Octagon / OctagonPanel "Ward" Android RAT Impersonates works
A four-stage Android RAT tracked as Octagon/OctagonPanel, built on a component set researchers call the "Ward" framework, impersonates Bahrain's official BH Alert emergency-notification app (and MyGov Bahrain, the Interior Ministry, and the Information & eGovernment Authority) to trick victims into sideloading a trojanized APK. It abuses VPN and Accessibility Service permissions to harvest lock-screen PINs/patterns, intercept SMS/OTPs, run banking-app phishing overlays, capture screenshots, and exfiltrate contacts/call logs to a hardcoded C2 at 209.99.184.50:4444 using RC4-encrypted, dynamically loaded DEX/JAR payloads.
In mid-July 2026, amid heightened Gulf-region tension and civil-defense siren activations in Bahrain and Kuwait following regional missile threats, Dream Research Lab (an Abu Dhabi-based sovereign-AI/national cyberdefense firm) first identified (2026-07-17) a malicious Android campaign spoofing Bahrain's official "BH Alert" emergency-alert application, and published its original technical research blog disclosing the campaign publicly on 2026-07-20. The trojanized app was distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government portals (Civil Defence, Interior Ministry, and Information & eGovernment Authority branding) — complete with fake install-progress animations and ad-tracking pixels to look legitimate — as well as via smishing links shared on social media and messaging platforms. Fabricated listings claimed over 100,000 downloads with fake reviews to appear legitimate. Dream noted the campaign relies on social engineering and abuse of legitimate Android permissions, delivered under a public-safety brand at the exact moment users are primed to install it; the same vendor had previously documented a similar trojanized Israeli "Red Alert" civil-defense siren app (approx. March 2026) used for silent surveillance data collection, indicating this public-safety-brand playbook is a repeat tactic rather than a one-off.
The malware runs a four-stage infection chain: a package named 'Ematterassist' acts as an RC4-encrypted stage-0 loader hidden inside a font asset (ZfChs.ttf), which decrypts to ZfChs.dex and is loaded at runtime via DexClassLoader; 'com.kit.kitty' presents the stage-1 social-engineering UI that walks the victim through granting permissions under the guise of enabling emergency alerts; 'Hvoicemanual' is an RC4-encrypted stage-2 shell that decrypts the main payload; and 'com.kisa.octagonpanel' is the stage-3 payload — the OctagonPanel RAT itself, built on the "Ward" framework (evidenced by the malicious 'WardAccessibilityService' component). A dynamically generated child JAR (ZGdSEl.jar, staged under com.kisa.octagonpanel's app_walk directory) can be produced/installed at runtime, and the AndroidManifest declares classes that do not exist at install time, only materializing after in-memory/streamed installation via the PackageInstaller API — a design intended to defeat static analysis.
Once installed, the malware requests VPN-service permission (to intercept and filter device traffic while maintaining its own outbound channel), Accessibility Service (to monitor lock-screen unlock events and capture PINs/passwords/patterns, and to run phishing overlays on top of legitimate banking apps), and Install-Unknown-Apps (to sideload the child APK/JAR). Harvested lock-screen credentials are written locally to captured_passwords.json; SMS messages (including one-time passwords), contacts, and call logs are collected; screenshots and UI state are captured; and stolen data is staged in a local SQLite database (octagon_ward.db) before being transmitted to a hardcoded C2 server at 209.99.184.50 on TCP port 4444, with the C2 configuration itself persisted client-side in a SharedPreferences file named octagon.xml. Persistence is maintained through boot receivers, foreground services, watchdog processes, and abuse of Android's AccountManager/SyncAdapter framework (a 'SyncHelper' class registers a fake 'OctagonPanel' account to trigger periodic ~30-minute wakeups).
Coverage rippled outward from Dream's 2026-07-20 blog through Dark Reading (2026-07-22), Bahraini outlets GDN Online and Gulf News (2026-07-22), Cyber Security News (2026-07-23), The Hacker News's ThreatsDay roundup (2026-07-23), and TeamWin/Mallory.ai (2026-07-24), before K7 Security Labs independently published its own deeper technical analysis on 2026-08-03, confirming the package names, hashes, C2 endpoint, and RC4/DexClassLoader loading chain. No CVE applies — this is a malicious trojanized application distributed via social engineering, not a software vulnerability. Attribution is unconfirmed; one outlet raised the possibility of state-sponsored or politically motivated activity given the geopolitical backdrop, but no threat actor, group, or nation-state has been named with confidence by any source, and the well-evidenced capability set (banking overlays, OTP theft, credential harvesting) is equally consistent with financially motivated mobile-banking fraud.
MITRE ATT&CK techniques used in TL-2026-1832
Persistence
T1398 Boot or Logon Initialization Scripts; T1541 Foreground Persistence; T1624 Event Triggered Execution
Defense Evasion
T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1541 Foreground Persistence; T1632 Subvert Trust Controls; T1655 Masquerading
Credential Access
T1417 Input Capture; T1453 Abuse Accessibility Features
Collection
T1417 Input Capture; T1453 Abuse Accessibility Features; T1513 Screen Capture; T1533 Data from Local System; T1636 Protected User Data
Discovery
T1426 System Information Discovery
Command and Control
T1437 Application Layer Protocol; T1509 Non-Standard Port; T1521 Encrypted Channel; T1544 Ingress Tool Transfer; T1663 Remote Access Software
Privilege Escalation
T1626 Abuse Elevation Control Mechanism
Exfiltration
T1646 Exfiltration Over C2 Channel
Initial Access
Affected products and versions in Octagon / OctagonPanel "Ward" Android RAT Impersonates
- N/A (malicious third-party APK, not an official vendor product) — Trojanized "BH Alert" / "MyGov Bahrain" Android application impersonating Bahrain Civil Defence, the Interior Ministry, and the Information & eGovernment Authority
Vulnerable versions: Any APK obtained from download.alertbh.info, bh-alert.com, playgoogle.bh-alert.com, playgoogle.alertbh.com, download.alert-bh.com, download.bh-security.com, fake Google Play clone pages, or smishing/social-media links
Fixed in: N/A — not an official application; users must uninstall any sideloaded copy and only install BH Alert / MyGov Bahrain from the official Google Play Store listing
Remediation for Octagon / OctagonPanel "Ward" Android RAT Impersonates
Immediate actions
- Block outbound connections to C2 server 209.99.184.50 (TCP/4444) at network egress/firewall and mobile carrier level
- Block/sinkhole the known distribution and phishing infrastructure: download.alertbh.info, bh-alert.com, playgoogle.bh-alert.com, playgoogle.alertbh.com, download.alert-bh.com, download.bh-security.com
- Identify and uninstall any installed app matching package names com.kit.kitty, com.kisa.octagonpanel, Ematterassist, or Hvoicemanual; treat the device as compromised and perform a full factory reset
- Force password/PIN reset and revoke active sessions for any banking, BH Alert, or MyGov Bahrain accounts accessed from a suspected-infected device, and re-enroll MFA/OTP on a clean device
- Advise affected users to enable Google Play Protect and disable the 'Install unknown apps' permission for any app that requested it during the infection chain
Workarounds
- Only install BH Alert or MyGov Bahrain from the official Google Play Store listing published by the Government of the Kingdom of Bahrain; verify the publisher identity before installing
- Do not click APK download links received via SMS, social media, or messaging apps even when branded as an official emergency-alert or government application
Longer-term hardening
- Deploy Mobile Threat Defense (MTD) / EMM tooling on managed fleets with detection for Accessibility-Service abuse, unusual VPN-service registration, and dynamic DEX/JAR class loading
- Restrict installation sources to the official Google Play Store listing verified against the Government of Bahrain's official publisher identity; block sideloading via MDM policy on managed/BYOD devices with access to corporate or banking apps
- Run a public-awareness campaign (in partnership with Bahraini and Kuwaiti authorities) warning citizens against installing emergency-alert apps from links shared via SMS/social media rather than the official Play Store listing, especially during active regional crisis periods
- Add banking-app accessibility-overlay and screen-capture-permission grants as a high-priority signal in mobile EDR/MTD monitoring for financial-sector customers
- Track the recurring 'trojanized public-safety app' playbook (this campaign and the prior March 2026 Israeli 'Red Alert' clone) as a named pattern in threat models for any government or civil-defense mobile app across the region
Timeline of Octagon / OctagonPanel "Ward" Android RAT Impersonates
- Dream Research Lab (the vendor that would later uncover Octagon) previously documented a trojanized Israeli 'Red Alert' civil-defense siren app used for silent surveillance data collection, establishing the same public-safety-brand social-engineering playbook later reused against Bahrain's BH Alert app. Exact day within March 2026 not specified in secondary reporting (The Hacker News ThreatsDay bulletin).
- Dream Research Lab first identifies and analyzes the Octagon/OctagonPanel "Ward" Android RAT campaign impersonating Bahrain's BH Alert emergency-alert app.
- Dream Research Lab publishes its original technical research blog, disclosing the four-stage OctagonPanel/Ward infection chain and the fake BH Alert campaign to the public for the first time.
- Gulf News reports on the fake Bahrain alert app warning, amplifying the Dream Research Lab findings to a wider regional audience.
- Bahraini media outlet GDN Online publishes a public warning about the fake BH Alert app based on Dream Research Lab's findings; unnamed authorities advise users to verify apps via official websites and social accounts before installing.
- Dark Reading reports on Dream Research Lab's findings, detailing the four-stage surveillance platform's credential-harvesting, OTP-interception, and banking-overlay capabilities and its exploitation of regional missile-threat anxiety.
- The Hacker News includes the campaign in its ThreatsDay bulletin, adding detail on the look-alike Google Play/government-site clone network's fake install-progress animations and ad-tracking pixels, and citing Dream's prior March 2026 Israeli 'Red Alert' campaign as a comparable precedent.
- Cyber Security News publishes a detailed technical writeup of the four-stage OctagonPanel/Ward infection chain, including package names (Ematterassist, com.kit.kitty, Hvoicemanual, com.kisa.octagonpanel), fake distribution domains, and banking-overlay/persistence behavior.
- Mallory.ai and TeamWin.in republish and expand on the Dream Research Lab analysis, noting the campaign's exploitation of Gulf-region civil-defense activations and speculating on a possible state-sponsored or politically motivated angle.
- TL-Intel Harness ingests the K7 Security Labs report via the K7 Security Labs RSS feed and opens tracked threat TL-2026-1832.
- K7 Security Labs independently publishes its own deep technical analysis ("Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application"), confirming package hashes for com.kit.kitty and com.kisa.octagonpanel, the hardcoded C2 endpoint 209.99.184.50:4444, and the RC4/DexClassLoader dynamic-loading chain.
Sources cited for Octagon / OctagonPanel "Ward" Android RAT Impersonates
- Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
- Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
- Fake Bahrain Alert App Deploys Android Surveillance Malware
- Fake Bahrain Civil Defense App Spreads Android RAT for Credential and SMS Theft
- Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
- Bahrain News: Fake alert app warning
- Think before you download: Cyber firm warns of fake Bahrain alert app
- GDN Online: warning against fake Bahrain Civil Defence emergency alert app
- ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
- MITRE ATT&CK for Mobile Matrix (tactic/technique reference used for TTP mapping)
Detection coverage for TL-2026-1832
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1832 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1832
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.