Threat reportMalwareTL-2026-1881

Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload

criticalACTIVE

Octagon Android RAT (TL-2026-1881), also tracked as OctagonPanel, is a critical-severity malware campaign, first published 2026-08-05. It has no confirmed attribution, affects Android Android OS (devices that allow sideloading), maps to 20 MITRE ATT&CK techniques (T1406, T1407, T1417), and is covered by 9 detection rules and 47 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
47Indicators of compromise

Key facts for TL-2026-1881

Threat ID
TL-2026-1881
Also known as
OctagonPanel, Ward RAT, BH Alert impersonator, Fake Bahrain Civil Defense App
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
public-safety, civil-defense, government administration, general-public, telecoms
Target regions
Middle East, bahrain
Detection rules
9
Indicators of compromise
47

Malware and tooling in Octagon Android RAT

Malware and tooling: Octagon, OctagonPanel, Trojan, Ward, FenrirVpnService

How Octagon Android RAT works

Zimperium zLabs and K7 Labs report Octagon, an emerging multi-stage Android RAT distributed via fake 'BH Alert' Civil Defense apps impersonating Bahrain government emergency-communication services. The malware uses RC4/AES-256-GCM-encrypted payloads loaded via DexClassLoader, abuses Accessibility Services through a deceptive 7-step onboarding process, and establishes malicious VPN tunnels for traffic interception. Capabilities include keylogging, credential theft, SMS/contacts/call-log harvesting, phishing overlays, persistent C2 on a non-standard port, and multi-layer persistence (boot receivers, watchdog services, 30-minute account sync).

Octagon is a multi-stage Android Remote Access Trojan first publicly named by K7 Computing Labs (author: Baran S., published 2026-08-03) and independently documented by Zimperium zLabs the following day. The campaign impersonates the official 'BH Alert' civil-defense/emergency application used by Bahrain's Ministry of Interior and UNDRR, and is delivered through a phishing infrastructure of fake Google Play pages and spoofed government download sites that serve a 20 MB 'BH-Alert.apk' outside official app stores. The primary dropper (package com.kit.kitty) creates a launcher icon mimicking the legitimate MyGov – Bahrain app and walks victims through a 7-step setup wizard that coerces several dangerous permissions: Accessibility Service, VPN, 'Install Unknown Apps', and standard SMS/contacts grants.

The malware employs a four-stage decoupled architecture. Stage 0 (com.old.stem.Ematterassist) is an outer RC4 shell (key 'ct') that injects the BH Alert installer DEX; Stage 1 (com.kit.kitty) is the lure that coerces permissions and installs the child APK; Stage 2 (biz.rely.melt.Hvoicemanual) is a nested RC4 shell (key 'NYrGT') that injects the core RAT DEX; Stage 3 (com.kisa.octagonpanel) is the operational RAT. Payload DEX is encrypted as a disguised font file (assets/ZfChs.ttf), decrypted on-device via an RC4 routine, written to private storage as ZfChs.dex, and loaded at runtime with DexClassLoader — resolving manifest class declarations that do not exist in the primary classes.dex to defeat static analysis. End-to-end C2 traffic is protected with AES-256-GCM (256-bit key derived via SHA-256 of passphrase 'octagon-default-key-change-me', 12-byte nonce, 128-bit auth tag), with build ID 'DevLRT' and protocol version 2.

After obtaining VPN permission, the FenrirVpnService establishes a malicious VPN tunnel assigning 10.0.0.1/24 with default routes and advertised DNS, but processPacket always returns null — routing all device traffic except an allow-listed set of apps (messengers, social apps, the malware packages) into a blackhole, enabling network-layer traffic interception and hijacking while the device appears functional for excluded apps. The child RAT is installed in-memory via Android PackageInstaller sessions without writing a standalone APK to disk, then launches com.kisa.octagonpanel, which generates and dynamically loads ZGdSEl.jar via dex2oat.

OctagonPanel's surveillance capabilities include: Accessibility-based keylogging of lock-screen PINs/passwords/patterns (LockscreenPasswordCapture, stored in captured_passwords.json with a 200-entry rolling history), SMS/WAP interception with default-SMS-app registration (SmsReceiver, WapPushReceiver, HeadlessSmsSendService), contact and call-log harvesting, screen capture via Accessibility and MediaProjection, real-time UI-overlay phishing (GateOverlayActivity launching on foreground-package match against an operator-controlled gate list), and remote UI control (node actions, package launch, click triggers, watchers, screen dimming). Stolen data is persisted in a local SQLite database (octagon_ward.db) for operation during network interruptions and synced to C2 later.

Persistence is defense-in-depth: boot receivers (BOOT_COMPLETED), a ServiceWatchdog combining AlarmManager, WorkManager and expedited restart paths, a GuardService in a separate :guard process, an anti-removal monitor (anti_remover/anti_remover_moni), and a SyncHelper that registers a fake 'OctagonPanel' account via Android AccountManager/SyncAdapter framework to wake the malware every 30 minutes — preserving runtime state, C2 config, and removal resistance across reboots. C2 is 209.99.184.50:4444 (non-standard port), with a secondary launcher host www.murlauncher.com/fenrir-launcher and a Guardian protocol (types 48-65) that can swap C2 infrastructure on demand. Attribution is unconfirmed; DreamGroup notes Russian-speaking actor indicators (Cyrillic strings, 'kisa' shared across package names) but explicitly states there is no nation-state evidence.

MITRE ATT&CK techniques used in TL-2026-1881

defense-evasion

T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1628 Hide Artifacts; T1629 Impair Defenses

collection

T1417 Input Capture; T1429 Audio Capture; T1636.004 SMS Messages

Discovery

T1418 Software Discovery

Collection

T1430 Location Tracking; T1513 Screen Capture; T1636.002 Call Log

command-and-control

T1437 Application Layer Protocol

Impact

T1464 Network Denial of Service

Persistence

T1541 Foreground Persistence; T1603 Scheduled Task/Job; T1624 Event Triggered Execution

Command and Control

T1572 Protocol Tunneling; T1573 Encrypted Channel

privilege-escalation

T1626 Abuse Elevation Control Mechanism

Initial Access

T1660 Phishing

Affected products and versions in Octagon Android RAT

  • Android — Android OS (devices that allow sideloading)
    Vulnerable versions: All Android versions that allow installation from unknown sources
    Fixed in: No vendor patch — mitigation is endpoint protection and user awareness

Remediation for Octagon Android RAT

Patches

  • No CVE — keep Android OS and Play Protect updated to the current version

Immediate actions

  • Block C2 IP 209.99.184.50 and all Octagon phishing domains (alertbh*, alert-bh*, bh-security*, bh-alert*, playgoogle*) at the perimeter and DNS
  • Deploy mobile threat defense (MTD) with behavioral/anomaly detection; block connections to known Octagon C2 and hosting domains
  • Instruct users to uninstall any 'BH Alert' app not installed from the official store and change credentials from a trusted device

Workarounds

  • Disable Accessibility Service grants to untrusted apps
  • Review and remove unsigned/unofficial apps granted Accessibility, VPN, SMS, or Install-Unknown-Apps permissions

Longer-term hardening

  • Hunt for the kitty-to-octagonpanel install chain followed by accessibility/SMS/dialer role changes
  • Detect VPNs with default routes but zero forwarded traffic excluding the VPN app plus one other package
  • Correlate 'Updating...' foreground notification with the Ward foreground service and :guard process
  • Restrict sideloading (Install Unknown Apps) and enforce enterprise app approval policies

Timeline of Octagon Android RAT

  • Octagon RAT sample (package com.kisa.octagonpanel, SHA-256 c6528aba...) submitted to Triage sandbox; behavioral analysis confirms runtime JAR loading via dex2oat, AccessibilityService abuse, foreground/guard/sync service persistence, and C2 209.99.184.50:4444.
  • K7 Computing Labs (author Baran S.) publishes the initial technical analysis of the fake Bahrain Civil Defense application, naming the malware 'Octagon' and documenting the multi-stage dynamic-loading design.
  • HEAL Security documents Octagon's reboot-resilient persistence (boot receivers, paired watchdog services, 30-minute fake 'OctagonPanel' account sync); Dark Reading covers the campaign targeting Bahrain during a period of regional tension.
  • Zimperium zLabs publishes 'Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware', describing the RC4-encrypted payload, DexClassLoader, Accessibility 7-step onboarding, and malicious VPN tunnel; claims detection preceded K7's public disclosure.
  • DreamGroup publishes a deep-dive detailing the four-stage architecture (Ematterassist/kitty/Hvoicemanual/octagonpanel), RC4 and AES-256-GCM encryption passphrase 'octagon-default-key-change-me', the Guardian C2 protocol, VPN blackhole mechanism, and the full domain/hash IOC set.
  • Zimperium MTD/zDefend continue to detect Octagon via behavior-based ML models (anomalous dynamic code execution, Accessibility abuse, C2/domain blocking) without requiring signature updates; campaign remains active.

Sources cited for Octagon Android RAT

Detection coverage for TL-2026-1881

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1881 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
47 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1881

4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats