# Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload

> Zimperium zLabs and K7 Labs report Octagon, an emerging multi-stage Android RAT distributed via fake 'BH Alert' Civil Defense apps impersonating Bahrain government emergency-communication services. The malware uses RC4/AES-256-GCM-encrypted payloads loaded via DexClassLoader, abuses Accessibility Services through a deceptive 7-step onboarding process, and establishes malicious VPN tunnels for traffic interception. Capabilities include keylogging, credential theft, SMS/contacts/call-log harvesting, phishing overlays, persistent C2 on a non-standard port, and multi-layer persistence (boot receivers, watchdog services, 30-minute account sync).

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1881
- **ID:** TL-2026-1881
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 47 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Octagon is a multi-stage Android Remote Access Trojan first publicly named by K7 Computing Labs (author: Baran S., published 2026-08-03) and independently documented by Zimperium zLabs the following day. The campaign impersonates the official 'BH Alert' civil-defense/emergency application used by Bahrain's Ministry of Interior and UNDRR, and is delivered through a phishing infrastructure of fake Google Play pages and spoofed government download sites that serve a 20 MB 'BH-Alert.apk' outside official app stores. The primary dropper (package com.kit.kitty) creates a launcher icon mimicking the legitimate MyGov – Bahrain app and walks victims through a 7-step setup wizard that coerces several dangerous permissions: Accessibility Service, VPN, 'Install Unknown Apps', and standard SMS/contacts grants.

The malware employs a four-stage decoupled architecture. Stage 0 (com.old.stem.Ematterassist) is an outer RC4 shell (key 'ct') that injects the BH Alert installer DEX; Stage 1 (com.kit.kitty) is the lure that coerces permissions and installs the child APK; Stage 2 (biz.rely.melt.Hvoicemanual) is a nested RC4 shell (key 'NYrGT') that injects the core RAT DEX; Stage 3 (com.kisa.octagonpanel) is the operational RAT. Payload DEX is encrypted as a disguised font file (assets/ZfChs.ttf), decrypted on-device via an RC4 routine, written to private storage as ZfChs.dex, and loaded at runtime with DexClassLoader — resolving manifest class declarations that do not exist in the primary classes.dex to defeat static analysis. End-to-end C2 traffic is protected with AES-256-GCM (256-bit key derived via SHA-256 of passphrase 'octagon-default-key-change-me', 12-byte nonce, 128-bit auth tag), with build ID 'DevLRT' and protocol version 2.

After obtaining VPN permission, the FenrirVpnService establishes a malicious VPN tunnel assigning 10.0.0.1/24 with default routes and advertised DNS, but processPacket always returns null — routing all device traffic except an allow-listed set of apps (messengers, social apps, the malware packages) into a blackhole, enabling network-layer traffic interception and hijacking while the device appears functional for excluded apps. The child RAT is installed in-memory via Android PackageInstaller sessions without writing a standalone APK to disk, then launches com.kisa.octagonpanel, which generates and dynamically loads ZGdSEl.jar via dex2oat.

OctagonPanel's surveillance capabilities include: Accessibility-based keylogging of lock-screen PINs/passwords/patterns (LockscreenPasswordCapture, stored in captured_passwords.json with a 200-entry rolling history), SMS/WAP interception with default-SMS-app registration (SmsReceiver, WapPushReceiver, HeadlessSmsSendService), contact and call-log harvesting, screen capture via Accessibility and MediaProjection, real-time UI-overlay phishing (GateOverlayActivity launching on foreground-package match against an operator-controlled gate list), and remote UI control (node actions, package launch, click triggers, watchers, screen dimming). Stolen data is persisted in a local SQLite database (octagon_ward.db) for operation during network interruptions and synced to C2 later.

Persistence is defense-in-depth: boot receivers (BOOT_COMPLETED), a ServiceWatchdog combining AlarmManager, WorkManager and expedited restart paths, a GuardService in a separate :guard process, an anti-removal monitor (anti_remover/anti_remover_moni), and a SyncHelper that registers a fake 'OctagonPanel' account via Android AccountManager/SyncAdapter framework to wake the malware every 30 minutes — preserving runtime state, C2 config, and removal resistance across reboots. C2 is 209.99.184.50:4444 (non-standard port), with a secondary launcher host www.murlauncher.com/fenrir-launcher and a Guardian protocol (types 48-65) that can swap C2 infrastructure on demand. Attribution is unconfirmed; DreamGroup notes Russian-speaking actor indicators (Cyrillic strings, 'kisa' shared across package names) but explicitly states there is no nation-state evidence.

## MITRE ATT&CK

- T1660 Phishing
- T1407 Download New Code at Runtime
- T1429 Audio Capture
- T1624 Event Triggered Execution
- T1603 Scheduled Task/Job
- T1541 Foreground Persistence
- T1626 Abuse Elevation Control Mechanism
- T1406 Obfuscated Files or Information
- T1628 Hide Artifacts
- T1629 Impair Defenses
- T1417 Input Capture
- T1636.004 SMS Messages
- T1513 Screen Capture
- T1430 Location Tracking
- T1636.002 Call Log
- T1418 Software Discovery
- T1437 Application Layer Protocol
- T1573 Encrypted Channel
- T1572 Protocol Tunneling
- T1464 Network Denial of Service

## Sources

- [Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware](https://zimperium.com/blog/rapid-response-zimperium-secures-mobile-endpoints-against-octagon-android-malware)
- [Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application (K7 Labs)](https://labs.k7computing.com/index.php/octagon-technical-analysis-of-a-fake-bahrain-civil-defense-application/)
- [How a Fake Bahrain Civil-Defense App Turns a Phone Into a Listening Post (DreamGroup)](https://dreamgroup.com/blog/how-a-fake-bahrain-civil-defense-app-turns-a-phone-into-a-listening-post)
- [Fake Bahrain Alert App Deploys Android Surveillance Malware (Dark Reading)](https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware)
- [Android RAT Survives Reboots Using Watchdog Services and Boot Receivers (HEAL Security)](https://healsecurity.com/android-rat-survives-reboots-using-watchdog-services-and-boot-receivers/)
- [Triage Analysis: Octagon sample 260728-hy1fda1ybw](https://tria.ge/260728-hy1fda1ybw/behavioral4)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1881
