# Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data

> A four-stage Android RAT tracked as Octagon/OctagonPanel, built on a component set researchers call the "Ward" framework, impersonates Bahrain's official BH Alert emergency-notification app (and MyGov Bahrain, the Interior Ministry, and the Information & eGovernment Authority) to trick victims into sideloading a trojanized APK. It abuses VPN and Accessibility Service permissions to harvest lock-screen PINs/patterns, intercept SMS/OTPs, run banking-app phishing overlays, capture screenshots, and exfiltrate contacts/call logs to a hardcoded C2 at 209.99.184.50:4444 using RC4-encrypted, dynamically loaded DEX/JAR payloads.

- **Published:** 2026-08-03T00:00:00Z
- **Last reviewed:** 2026-08-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1832
- **ID:** TL-2026-1832
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In mid-July 2026, amid heightened Gulf-region tension and civil-defense siren activations in Bahrain and Kuwait following regional missile threats, Dream Research Lab (an Abu Dhabi-based sovereign-AI/national cyberdefense firm) first identified (2026-07-17) a malicious Android campaign spoofing Bahrain's official "BH Alert" emergency-alert application, and published its original technical research blog disclosing the campaign publicly on 2026-07-20. The trojanized app was distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government portals (Civil Defence, Interior Ministry, and Information & eGovernment Authority branding) — complete with fake install-progress animations and ad-tracking pixels to look legitimate — as well as via smishing links shared on social media and messaging platforms. Fabricated listings claimed over 100,000 downloads with fake reviews to appear legitimate. Dream noted the campaign relies on social engineering and abuse of legitimate Android permissions, delivered under a public-safety brand at the exact moment users are primed to install it; the same vendor had previously documented a similar trojanized Israeli "Red Alert" civil-defense siren app (approx. March 2026) used for silent surveillance data collection, indicating this public-safety-brand playbook is a repeat tactic rather than a one-off.

The malware runs a four-stage infection chain: a package named 'Ematterassist' acts as an RC4-encrypted stage-0 loader hidden inside a font asset (ZfChs.ttf), which decrypts to ZfChs.dex and is loaded at runtime via DexClassLoader; 'com.kit.kitty' presents the stage-1 social-engineering UI that walks the victim through granting permissions under the guise of enabling emergency alerts; 'Hvoicemanual' is an RC4-encrypted stage-2 shell that decrypts the main payload; and 'com.kisa.octagonpanel' is the stage-3 payload — the OctagonPanel RAT itself, built on the "Ward" framework (evidenced by the malicious 'WardAccessibilityService' component). A dynamically generated child JAR (ZGdSEl.jar, staged under com.kisa.octagonpanel's app_walk directory) can be produced/installed at runtime, and the AndroidManifest declares classes that do not exist at install time, only materializing after in-memory/streamed installation via the PackageInstaller API — a design intended to defeat static analysis.

Once installed, the malware requests VPN-service permission (to intercept and filter device traffic while maintaining its own outbound channel), Accessibility Service (to monitor lock-screen unlock events and capture PINs/passwords/patterns, and to run phishing overlays on top of legitimate banking apps), and Install-Unknown-Apps (to sideload the child APK/JAR). Harvested lock-screen credentials are written locally to captured_passwords.json; SMS messages (including one-time passwords), contacts, and call logs are collected; screenshots and UI state are captured; and stolen data is staged in a local SQLite database (octagon_ward.db) before being transmitted to a hardcoded C2 server at 209.99.184.50 on TCP port 4444, with the C2 configuration itself persisted client-side in a SharedPreferences file named octagon.xml. Persistence is maintained through boot receivers, foreground services, watchdog processes, and abuse of Android's AccountManager/SyncAdapter framework (a 'SyncHelper' class registers a fake 'OctagonPanel' account to trigger periodic ~30-minute wakeups).

Coverage rippled outward from Dream's 2026-07-20 blog through Dark Reading (2026-07-22), Bahraini outlets GDN Online and Gulf News (2026-07-22), Cyber Security News (2026-07-23), The Hacker News's ThreatsDay roundup (2026-07-23), and TeamWin/Mallory.ai (2026-07-24), before K7 Security Labs independently published its own deeper technical analysis on 2026-08-03, confirming the package names, hashes, C2 endpoint, and RC4/DexClassLoader loading chain. No CVE applies — this is a malicious trojanized application distributed via social engineering, not a software vulnerability. Attribution is unconfirmed; one outlet raised the possibility of state-sponsored or politically motivated activity given the geopolitical backdrop, but no threat actor, group, or nation-state has been named with confidence by any source, and the well-evidenced capability set (banking overlays, OTP theft, credential harvesting) is equally consistent with financially motivated mobile-banking fraud.

## MITRE ATT&CK

- T1660 Phishing
- T1398 Boot or Logon Initialization Scripts
- T1624 Event Triggered Execution
- T1541 Foreground Persistence
- T1626 Abuse Elevation Control Mechanism
- T1407 Download New Code at Runtime
- T1406 Obfuscated Files or Information
- T1655 Masquerading
- T1541 Foreground Persistence
- T1632 Subvert Trust Controls
- T1453 Abuse Accessibility Features
- T1417 Input Capture
- T1426 System Information Discovery
- T1453 Abuse Accessibility Features
- T1636 Protected User Data
- T1513 Screen Capture
- T1533 Data from Local System
- T1417 Input Capture
- T1437 Application Layer Protocol
- T1521 Encrypted Channel
- T1509 Non-Standard Port
- T1663 Remote Access Software
- T1544 Ingress Tool Transfer
- T1646 Exfiltration Over C2 Channel

## Sources

- [Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application](https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/)
- [Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials](https://cybersecuritynews.com/fake-bahrain-civil-defense-android-app/)
- [Fake Bahrain Alert App Deploys Android Surveillance Malware](https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware)
- [Fake Bahrain Civil Defense App Spreads Android RAT for Credential and SMS Theft](https://mallory.ai/stories/019f8ba9-e207-7dc9-bcbc-a42a2609e123)
- [Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials](https://teamwin.in/fake-bahrain-civil-defense-app-deploys-android-rat-to-steal-pins-otps-and-banking-credentials/)
- [Bahrain News: Fake alert app warning](https://www.gdnonline.com/Details/1401276)
- [Think before you download: Cyber firm warns of fake Bahrain alert app](https://gulfnews.com/technology/think-before-you-download-cyber-firm-warns-of-fake-bahrain-alert-app-1.500625694)
- [GDN Online: warning against fake Bahrain Civil Defence emergency alert app](https://x.com/GDNonline/status/2079837884060774460)
- [ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories](https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html)
- [MITRE ATT&CK for Mobile Matrix (tactic/technique reference used for TTP mapping)](https://attack.mitre.org/matrices/mobile/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1832
