Threat reportMalwareTL-2026-1881
Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload
Octagon Android RAT (TL-2026-1881), also tracked as OctagonPanel, is a critical-severity malware campaign, first published 2026-08-05. It has no confirmed attribution, affects Android Android OS (devices that allow sideloading), maps to 20 MITRE ATT&CK techniques (T1406, T1407, T1417), and is covered by 9 detection rules and 47 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 47Indicators of compromise
Key facts for TL-2026-1881
- Threat ID
- TL-2026-1881
- Also known as
- OctagonPanel, Ward RAT, BH Alert impersonator, Fake Bahrain Civil Defense App
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- public-safety, civil-defense, government administration, general-public, telecoms
- Target regions
- Middle East, bahrain
- Detection rules
- 9
- Indicators of compromise
- 47
Malware and tooling in Octagon Android RAT
Malware and tooling: Octagon, OctagonPanel, Trojan, Ward, FenrirVpnService
How Octagon Android RAT works
Zimperium zLabs and K7 Labs report Octagon, an emerging multi-stage Android RAT distributed via fake 'BH Alert' Civil Defense apps impersonating Bahrain government emergency-communication services. The malware uses RC4/AES-256-GCM-encrypted payloads loaded via DexClassLoader, abuses Accessibility Services through a deceptive 7-step onboarding process, and establishes malicious VPN tunnels for traffic interception. Capabilities include keylogging, credential theft, SMS/contacts/call-log harvesting, phishing overlays, persistent C2 on a non-standard port, and multi-layer persistence (boot receivers, watchdog services, 30-minute account sync).
Octagon is a multi-stage Android Remote Access Trojan first publicly named by K7 Computing Labs (author: Baran S., published 2026-08-03) and independently documented by Zimperium zLabs the following day. The campaign impersonates the official 'BH Alert' civil-defense/emergency application used by Bahrain's Ministry of Interior and UNDRR, and is delivered through a phishing infrastructure of fake Google Play pages and spoofed government download sites that serve a 20 MB 'BH-Alert.apk' outside official app stores. The primary dropper (package com.kit.kitty) creates a launcher icon mimicking the legitimate MyGov – Bahrain app and walks victims through a 7-step setup wizard that coerces several dangerous permissions: Accessibility Service, VPN, 'Install Unknown Apps', and standard SMS/contacts grants.
The malware employs a four-stage decoupled architecture. Stage 0 (com.old.stem.Ematterassist) is an outer RC4 shell (key 'ct') that injects the BH Alert installer DEX; Stage 1 (com.kit.kitty) is the lure that coerces permissions and installs the child APK; Stage 2 (biz.rely.melt.Hvoicemanual) is a nested RC4 shell (key 'NYrGT') that injects the core RAT DEX; Stage 3 (com.kisa.octagonpanel) is the operational RAT. Payload DEX is encrypted as a disguised font file (assets/ZfChs.ttf), decrypted on-device via an RC4 routine, written to private storage as ZfChs.dex, and loaded at runtime with DexClassLoader — resolving manifest class declarations that do not exist in the primary classes.dex to defeat static analysis. End-to-end C2 traffic is protected with AES-256-GCM (256-bit key derived via SHA-256 of passphrase 'octagon-default-key-change-me', 12-byte nonce, 128-bit auth tag), with build ID 'DevLRT' and protocol version 2.
After obtaining VPN permission, the FenrirVpnService establishes a malicious VPN tunnel assigning 10.0.0.1/24 with default routes and advertised DNS, but processPacket always returns null — routing all device traffic except an allow-listed set of apps (messengers, social apps, the malware packages) into a blackhole, enabling network-layer traffic interception and hijacking while the device appears functional for excluded apps. The child RAT is installed in-memory via Android PackageInstaller sessions without writing a standalone APK to disk, then launches com.kisa.octagonpanel, which generates and dynamically loads ZGdSEl.jar via dex2oat.
OctagonPanel's surveillance capabilities include: Accessibility-based keylogging of lock-screen PINs/passwords/patterns (LockscreenPasswordCapture, stored in captured_passwords.json with a 200-entry rolling history), SMS/WAP interception with default-SMS-app registration (SmsReceiver, WapPushReceiver, HeadlessSmsSendService), contact and call-log harvesting, screen capture via Accessibility and MediaProjection, real-time UI-overlay phishing (GateOverlayActivity launching on foreground-package match against an operator-controlled gate list), and remote UI control (node actions, package launch, click triggers, watchers, screen dimming). Stolen data is persisted in a local SQLite database (octagon_ward.db) for operation during network interruptions and synced to C2 later.
Persistence is defense-in-depth: boot receivers (BOOT_COMPLETED), a ServiceWatchdog combining AlarmManager, WorkManager and expedited restart paths, a GuardService in a separate :guard process, an anti-removal monitor (anti_remover/anti_remover_moni), and a SyncHelper that registers a fake 'OctagonPanel' account via Android AccountManager/SyncAdapter framework to wake the malware every 30 minutes — preserving runtime state, C2 config, and removal resistance across reboots. C2 is 209.99.184.50:4444 (non-standard port), with a secondary launcher host www.murlauncher.com/fenrir-launcher and a Guardian protocol (types 48-65) that can swap C2 infrastructure on demand. Attribution is unconfirmed; DreamGroup notes Russian-speaking actor indicators (Cyrillic strings, 'kisa' shared across package names) but explicitly states there is no nation-state evidence.
MITRE ATT&CK techniques used in TL-2026-1881
defense-evasion
T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1628 Hide Artifacts; T1629 Impair Defenses
collection
T1417 Input Capture; T1429 Audio Capture; T1636.004 SMS Messages
Discovery
Collection
T1430 Location Tracking; T1513 Screen Capture; T1636.002 Call Log
command-and-control
T1437 Application Layer Protocol
Impact
T1464 Network Denial of Service
Persistence
T1541 Foreground Persistence; T1603 Scheduled Task/Job; T1624 Event Triggered Execution
Command and Control
T1572 Protocol Tunneling; T1573 Encrypted Channel
privilege-escalation
T1626 Abuse Elevation Control Mechanism
Initial Access
Affected products and versions in Octagon Android RAT
- Android — Android OS (devices that allow sideloading)
Vulnerable versions: All Android versions that allow installation from unknown sources
Fixed in: No vendor patch — mitigation is endpoint protection and user awareness
Remediation for Octagon Android RAT
Patches
- No CVE — keep Android OS and Play Protect updated to the current version
Immediate actions
- Block C2 IP 209.99.184.50 and all Octagon phishing domains (alertbh*, alert-bh*, bh-security*, bh-alert*, playgoogle*) at the perimeter and DNS
- Deploy mobile threat defense (MTD) with behavioral/anomaly detection; block connections to known Octagon C2 and hosting domains
- Instruct users to uninstall any 'BH Alert' app not installed from the official store and change credentials from a trusted device
Workarounds
- Disable Accessibility Service grants to untrusted apps
- Review and remove unsigned/unofficial apps granted Accessibility, VPN, SMS, or Install-Unknown-Apps permissions
Longer-term hardening
- Hunt for the kitty-to-octagonpanel install chain followed by accessibility/SMS/dialer role changes
- Detect VPNs with default routes but zero forwarded traffic excluding the VPN app plus one other package
- Correlate 'Updating...' foreground notification with the Ward foreground service and :guard process
- Restrict sideloading (Install Unknown Apps) and enforce enterprise app approval policies
Timeline of Octagon Android RAT
- Octagon RAT sample (package com.kisa.octagonpanel, SHA-256 c6528aba...) submitted to Triage sandbox; behavioral analysis confirms runtime JAR loading via dex2oat, AccessibilityService abuse, foreground/guard/sync service persistence, and C2 209.99.184.50:4444.
- K7 Computing Labs (author Baran S.) publishes the initial technical analysis of the fake Bahrain Civil Defense application, naming the malware 'Octagon' and documenting the multi-stage dynamic-loading design.
- HEAL Security documents Octagon's reboot-resilient persistence (boot receivers, paired watchdog services, 30-minute fake 'OctagonPanel' account sync); Dark Reading covers the campaign targeting Bahrain during a period of regional tension.
- Zimperium zLabs publishes 'Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware', describing the RC4-encrypted payload, DexClassLoader, Accessibility 7-step onboarding, and malicious VPN tunnel; claims detection preceded K7's public disclosure.
- DreamGroup publishes a deep-dive detailing the four-stage architecture (Ematterassist/kitty/Hvoicemanual/octagonpanel), RC4 and AES-256-GCM encryption passphrase 'octagon-default-key-change-me', the Guardian C2 protocol, VPN blackhole mechanism, and the full domain/hash IOC set.
- Zimperium MTD/zDefend continue to detect Octagon via behavior-based ML models (anomalous dynamic code execution, Accessibility abuse, C2/domain blocking) without requiring signature updates; campaign remains active.
Sources cited for Octagon Android RAT
- Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware
- Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application (K7 Labs)
- How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post (DreamGroup)
- Fake Bahrain Alert App Deploys Android Surveillance Malware (Dark Reading)
- Android RAT Survives Reboots Using Watchdog Services and Boot Receivers (HEAL Security)
- Triage Analysis: Octagon sample 260728-hy1fda1ybw
Detection coverage for TL-2026-1881
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1881 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1881
4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.