Android users are now vulnerable to a new remote-access threat disguised as Bahrain’s BH Alert service This article explores source k7 security. . K7 Security Labs identified Octagon as a layered threat capable of stealing device unlock details, SMS messages, banking information, and other private data.
K7 Security Labs reported in a ZeroOwl document that the campaign primarily targeted users in Bahrain by impersonating the official emergency application called FakeBH Alert. This routine allows the malware to periodically wake up or respond on demand, enabling it to reconnect with its command server and maintain settings that include resistance against removal attempts. Request to install an unknown application (Source – K7 Security Labs) Users should steer clear of downloading software from unverified links in messages, social posts, or emergency pages.
Stick to official app stores for installation, verify developers' names, keep Android updated, and be wary when apps request access to features like Accessibility, VPN, SMS, or permissions to install other apps. Indicators of Compromise (IoCs): - Package name: com.kit.kitty - Initial malicious application package - File hash: 9694294addbe58be93ddbb6cabc499ce Hash associated with com.kit.kitty - Package name: com.kisa.octagonpanel - Child Android RAT package - File hash: 58330aaf1f533e9fe03b6355c60347b4 Hash associated with com.kisa.octagonpanel - C2 server: 209.99.184.50:4444 - Command-and-control server - URL: https://download.alertbh.info/BH-Alert.apk Malicious APK download location - URL: https://bh-alert.com/assets/BH-Alert.apk Malicious APK download location - URL: https://playgoogle.bh-alert.com Phishing infrastructure URL












