Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware SD-WAN Orchestrator Vulnerability Exploited in Attacks
August 3, 2026
Critical TP-Link TL-WR940N Flaw Lets Attackers Remotely Execute Code
August 3, 2026
ModernStealer Linked to Government and Defense Data Theft
August 3, 2026
Home/Threats/Android RAT Endures Reboots via Watchdog Services and Boot Receivers
Threats

Android RAT Endures Reboots via Watchdog Services and Boot Receivers

Key Takeaways A new Android remote access Trojan (RAT) named Octagon is actively targeting users, primarily in Bahrain. Octagon disguises itself as an official emergency alert application, “BH...

Sarah simpson
Sarah simpson
August 3, 2026 5 Min Read
2 0

Key Takeaways

  • A new Android remote access Trojan (RAT) named Octagon is actively targeting users, primarily in Bahrain.
  • Octagon disguises itself as an official emergency alert application, “BH Alert,” to trick victims into granting extensive permissions.
  • The malware employs sophisticated persistence mechanisms, including watchdog services and boot receivers, allowing it to survive device reboots.
  • It is capable of stealing sensitive data, including lock-screen credentials, SMS messages, banking information, and rerouting traffic via a deceptive VPN.
  • Users are strongly advised to only download applications from official app stores and exercise extreme caution with permission requests.

Android RAT Employs Advanced Persistence to Evade Detection and Steal Data

Android users are currently facing a significant threat from a novel remote access Trojan (RAT) known as Octagon. This sophisticated malware masquerades as a legitimate emergency alert service, “BH Alert,” specifically targeting individuals in Bahrain amidst regional tensions. Octagon’s design incorporates advanced persistence techniques, making it remarkably resilient to device reboots and challenging to remove, according to a recent analysis.

Table Of Content

  • Key Takeaways
  • Android RAT Employs Advanced Persistence to Evade Detection and Steal Data
  • Octagon’s Evasive Persistence Mechanisms
  • Credential Theft and Deceptive VPN Practices
  • What You Should Do

The campaign leverages public anxiety, directing victims to convincing phishing pages where they are prompted to download an Android application package (APK) outside of official app stores. The malicious app features a familiar-looking icon and uses urgent language to create a facade of legitimacy, thereby luring users into a multi-step installation process that grants the malware dangerous permissions.

K7 Security Labs said in a report that Octagon is a multi-layered Android threat. Its capabilities extend to exfiltrating critical personal information, including device unlock credentials, SMS content, and banking details. The malware’s architecture ensures that a simple device restart, often a common mitigation step, is ineffective, as its components are engineered to resume operation once the device powers back on.

Octagon’s Evasive Persistence Mechanisms

The infection chain for Octagon begins with an initial application, BH-Alert.apk, which guides users through a seven-step permission granting process. This initial app cleverly conceals its executable code within an encrypted file named ZfChs.ttf. This file is decrypted and loaded only when necessary, effectively limiting what basic security scans can detect at the initial stage.

Following the initial setup, the malware installs a secondary, “child” application referred to as OctagonPanel. It then generates additional code files at runtime. The core of Octagon’s resilience lies in its use of background services and “watchdog” processes. These watchdog components continuously monitor each other, ensuring that if one is terminated, its partner promptly restarts it. Furthermore, the malware utilizes Android’s boot receivers to automatically re-launch its malicious processes whenever the device is rebooted, rendering restarts largely ineffective in terminating the intrusion.

This method of achieving persistence aligns with a growing trend observed in other Android malware. Previous analyses of malicious Android TV compromises and other Android persistence cases have also highlighted the use of boot receivers, such as BOOT_COMPLETED, to reactivate harmful processes after a device restart.

Octagon further solidifies its persistence by creating a fake Android account, also named OctagonPanel, and scheduling it for synchronization every 30 minutes. This routine can periodically or on-demand awaken the malware, allowing it to re-establish connections with its command-and-control (C2) server and retrieve updated configurations, including instructions for resisting removal. This intricate design makes cleaning an infected device far more complex than merely uninstalling a visible application.

Researchers also discovered that Octagon maintains a local SQLite database to store its configuration, phishing templates, and intercepted communications. This local caching mechanism enables the malware to continue data collection even during temporary losses of internet connectivity, allowing the attackers to synchronize the stolen information later. All data exfiltration occurs over encrypted channels using a non-standard port to further evade detection.

Credential Theft and Deceptive VPN Practices

Once fully operational, Octagon prompts victims to enable the Accessibility Service and a VPN connection. The request for Accessibility Service is particularly insidious; while intended to assist users with disabilities, the malware abuses this permission to record lock-screen PINs, passwords, and patterns as they are entered. It can store a history of these captured credentials locally before transmitting them to the attackers.

The request for a VPN connection is equally deceptive. Instead of providing privacy or security, it redirects the victim’s internet traffic through an attacker-controlled tunnel. This allows the threat actors to intercept or manipulate sensitive online activities. To maintain a semblance of normalcy and reduce suspicion, a carefully selected list of applications is configured to bypass this malicious VPN tunnel.

The child application also possesses capabilities to harvest SMS messages, contact lists, call records, and screenshots. It can also overlay phishing pages onto targeted legitimate applications, tricking users into revealing further sensitive information. These functionalities bear resemblances to those found in other prominent Android threats, such as DroidBot banking malware, which exploited Accessibility services for keylogging and screen monitoring, and the RedHook RAT, known for its paired services that ensure mutual relaunch.

The Indicators of Compromise (IoCs) associated with Octagon include:

  • Package name: com.kit.kitty (Initial malicious application)
  • File hash: 9694294addbe58be93ddbb6cabc499ce (Associated with com.kit.kitty)
  • Package name: com.kisa.octagonpanel (Child Android RAT package)
  • File hash: 58330aaf1f533e9fe03b6355c60347b4 (Associated with com.kisa.octagonpanel)
  • C2 server: 209[.]99[.]184[.]50:4444
  • Malicious APK download URLs: https://download[.]alertbh[.]info/BH-Alert.apk, https://bh-alert[.]com/assets/BH-Alert.apk
  • Phishing infrastructure URL: https://playgoogle[.]bh-alert[.]com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Avoid Unofficial Sources: Never install applications from links received in messages, social media posts, or unverified websites, especially those claiming to be urgent alerts.
  • Use Official App Stores: Only download apps from trusted sources like the Google Play Store. Always verify the developer name and read reviews before installing.
  • Scrutinize Permissions: Be extremely cautious when an app requests sensitive permissions, particularly for Accessibility Service, VPN connections, SMS access, or the ability to install other applications. Understand what each permission entails before granting it.
  • Keep Android Updated: Ensure your Android operating system and all applications are kept up to date to benefit from the latest security patches.
  • Review and Remove: If you have downloaded “BH Alert” or any similar application from an unofficial source, immediately remove it from your device.
  • Change Credentials: After removal, review your account activity for any suspicious behavior and change all important credentials (banking, email, social media, etc.) from a trusted, clean device.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical SonicWall SMA Zero-Day Lets Attackers Remotely Compromise Appliances

Next Post

ModernStealer Linked to Government and Defense Data Theft

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
XCSSET v40 Malware Steals Cookies, Runs Commands via Chrome DevTools Protocol
August 3, 2026
MacSync macOS Stealer Targets Users With Fake Claude Guide
August 3, 2026
Critical Coldcard RNG Flaw Linked to $88.6 Million Bitcoin Theft
August 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us