Android RAT Endures Reboots via Watchdog Services and Boot Receivers
Key Takeaways A new Android remote access Trojan (RAT) named Octagon is actively targeting users, primarily in Bahrain. Octagon disguises itself as an official emergency alert application, “BH...
Key Takeaways
- A new Android remote access Trojan (RAT) named Octagon is actively targeting users, primarily in Bahrain.
- Octagon disguises itself as an official emergency alert application, “BH Alert,” to trick victims into granting extensive permissions.
- The malware employs sophisticated persistence mechanisms, including watchdog services and boot receivers, allowing it to survive device reboots.
- It is capable of stealing sensitive data, including lock-screen credentials, SMS messages, banking information, and rerouting traffic via a deceptive VPN.
- Users are strongly advised to only download applications from official app stores and exercise extreme caution with permission requests.
Android RAT Employs Advanced Persistence to Evade Detection and Steal Data
Android users are currently facing a significant threat from a novel remote access Trojan (RAT) known as Octagon. This sophisticated malware masquerades as a legitimate emergency alert service, “BH Alert,” specifically targeting individuals in Bahrain amidst regional tensions. Octagon’s design incorporates advanced persistence techniques, making it remarkably resilient to device reboots and challenging to remove, according to a recent analysis.
Table Of Content
The campaign leverages public anxiety, directing victims to convincing phishing pages where they are prompted to download an Android application package (APK) outside of official app stores. The malicious app features a familiar-looking icon and uses urgent language to create a facade of legitimacy, thereby luring users into a multi-step installation process that grants the malware dangerous permissions.
K7 Security Labs said in a report that Octagon is a multi-layered Android threat. Its capabilities extend to exfiltrating critical personal information, including device unlock credentials, SMS content, and banking details. The malware’s architecture ensures that a simple device restart, often a common mitigation step, is ineffective, as its components are engineered to resume operation once the device powers back on.
Octagon’s Evasive Persistence Mechanisms
The infection chain for Octagon begins with an initial application, BH-Alert.apk, which guides users through a seven-step permission granting process. This initial app cleverly conceals its executable code within an encrypted file named ZfChs.ttf. This file is decrypted and loaded only when necessary, effectively limiting what basic security scans can detect at the initial stage.
Following the initial setup, the malware installs a secondary, “child” application referred to as OctagonPanel. It then generates additional code files at runtime. The core of Octagon’s resilience lies in its use of background services and “watchdog” processes. These watchdog components continuously monitor each other, ensuring that if one is terminated, its partner promptly restarts it. Furthermore, the malware utilizes Android’s boot receivers to automatically re-launch its malicious processes whenever the device is rebooted, rendering restarts largely ineffective in terminating the intrusion.
This method of achieving persistence aligns with a growing trend observed in other Android malware. Previous analyses of malicious Android TV compromises and other Android persistence cases have also highlighted the use of boot receivers, such as BOOT_COMPLETED, to reactivate harmful processes after a device restart.
Octagon further solidifies its persistence by creating a fake Android account, also named OctagonPanel, and scheduling it for synchronization every 30 minutes. This routine can periodically or on-demand awaken the malware, allowing it to re-establish connections with its command-and-control (C2) server and retrieve updated configurations, including instructions for resisting removal. This intricate design makes cleaning an infected device far more complex than merely uninstalling a visible application.
Researchers also discovered that Octagon maintains a local SQLite database to store its configuration, phishing templates, and intercepted communications. This local caching mechanism enables the malware to continue data collection even during temporary losses of internet connectivity, allowing the attackers to synchronize the stolen information later. All data exfiltration occurs over encrypted channels using a non-standard port to further evade detection.
Credential Theft and Deceptive VPN Practices
Once fully operational, Octagon prompts victims to enable the Accessibility Service and a VPN connection. The request for Accessibility Service is particularly insidious; while intended to assist users with disabilities, the malware abuses this permission to record lock-screen PINs, passwords, and patterns as they are entered. It can store a history of these captured credentials locally before transmitting them to the attackers.
The request for a VPN connection is equally deceptive. Instead of providing privacy or security, it redirects the victim’s internet traffic through an attacker-controlled tunnel. This allows the threat actors to intercept or manipulate sensitive online activities. To maintain a semblance of normalcy and reduce suspicion, a carefully selected list of applications is configured to bypass this malicious VPN tunnel.
The child application also possesses capabilities to harvest SMS messages, contact lists, call records, and screenshots. It can also overlay phishing pages onto targeted legitimate applications, tricking users into revealing further sensitive information. These functionalities bear resemblances to those found in other prominent Android threats, such as DroidBot banking malware, which exploited Accessibility services for keylogging and screen monitoring, and the RedHook RAT, known for its paired services that ensure mutual relaunch.
The Indicators of Compromise (IoCs) associated with Octagon include:
- Package name:
com.kit.kitty(Initial malicious application) - File hash:
9694294addbe58be93ddbb6cabc499ce(Associated withcom.kit.kitty) - Package name:
com.kisa.octagonpanel(Child Android RAT package) - File hash:
58330aaf1f533e9fe03b6355c60347b4(Associated withcom.kisa.octagonpanel) - C2 server:
209[.]99[.]184[.]50:4444 - Malicious APK download URLs:
https://download[.]alertbh[.]info/BH-Alert.apk,https://bh-alert[.]com/assets/BH-Alert.apk - Phishing infrastructure URL:
https://playgoogle[.]bh-alert[.]com
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Avoid Unofficial Sources: Never install applications from links received in messages, social media posts, or unverified websites, especially those claiming to be urgent alerts.
- Use Official App Stores: Only download apps from trusted sources like the Google Play Store. Always verify the developer name and read reviews before installing.
- Scrutinize Permissions: Be extremely cautious when an app requests sensitive permissions, particularly for Accessibility Service, VPN connections, SMS access, or the ability to install other applications. Understand what each permission entails before granting it.
- Keep Android Updated: Ensure your Android operating system and all applications are kept up to date to benefit from the latest security patches.
- Review and Remove: If you have downloaded “BH Alert” or any similar application from an unofficial source, immediately remove it from your device.
- Change Credentials: After removal, review your account activity for any suspicious behavior and change all important credentials (banking, email, social media, etc.) from a trusted, clean device.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.