Octagon Android Bot Targets Financial Applications

Octagon Android bot control panel interface highlighting crypto wallet targeting and SMS interception

A novel Android malware variant currently enables cybercriminals to hijack a victim’s smartphone. This hijacking occurs specifically while the user interacts with banking applications and cryptocurrency wallets. Furthermore, the malware successfully intercepts confirmation codes and seamlessly replaces user interface elements. Security experts at iVerify initially discovered this threat, dubbed Octagon, in June 2026. A developer known as AndroidKitKat actively sells this program on underground cybercriminal forums for $1,400 monthly.

At a Glance: The Octagon Infection Model

The initial advertisements for Octagon surfaced on June 1. AndroidKitKat offers the malware via a strict subscription model. Subsequently, the developer announced the release of version 1.2 on June 29. Purchasers receive a pre-configured command-and-control panel for Windows, alongside the malicious Android application payload. Following a successful infection, the operator can actively browse installed programs and view the device screen in real time. Moreover, they can launch specific applications, remotely click buttons, input text, and execute complex gestures.

The Infection Chain and Technical Mechanism

Exploiting Android Accessibility Services

The Octagon Android bot primarily utilizes the standard Android Accessibility Services. If a user unwittingly grants the malicious application access to these services, the malware acquires comprehensive details regarding the interface elements of other running programs. Consequently, Octagon can dynamically render a fraudulent page directly over a legitimate application window. It then deceptively prompts the victim to enter their password, cryptocurrency wallet seed phrase, or other sensitive account credentials.

The malware currently features pre-built phishing templates specifically designed for Trust Wallet, Binance, and MEXC. Furthermore, purchasers possess the capability to integrate their own custom templates. The comprehensive control panel also intelligently identifies installed applications and reads displayed financial balances. The iVerify research team discovered that Octagon explicitly targets Trust Wallet, MetaMask, Binance, MEXC, and TON Keeper. The target list also includes popular communication platforms like Telegram, WhatsApp, and Viber. In the official release notes for version 1.1, the developer claimed to have integrated 457 distinct rules targeting various applications.

Intercepting SMS and Two-Factor Authentication

Octagon possesses the terrifying capability to intercept SMS messages and vital one-time authentication codes. It can also capture screenshots covertly and extract PINs, passwords, and graphical unlock patterns. One specific variant analyzed by researchers aggressively requested permissions to read, receive, and send SMS messages. Subsequently, it stealthily forwarded all incoming communications directly to the remote operator. Conversely, another variant harbored the interception functionality but did not explicitly request the required permission during the initial setup phase.

Command and Control Infrastructure

The Trojan establishes an encrypted connection with its command-and-control server utilizing TCP port 4444. Across all three distinct samples analyzed, specialists identified the identical com.kisa.octagonpanel package. They also found the WardAccessibilityService component, the Ward and Guardian command exchange mechanisms, and a standardized default keyphrase: octagon-default-key-change-me. However, the specific server addresses and the outward visual appearance of the decoy applications varied significantly between the samples.

Persistence and Evasion Tactics

The malware aggressively attempts to remain active for as long as possible following the initial installation. One specific variant automatically executes immediately after a device reboot. It utilizes an isolated background process, standard Android schedulers, battery optimization exemptions, and numerous other techniques to guarantee continuous operation. To effectively mask its malicious intent, the program might display entirely irrelevant, benign content. For instance, upon launching one analyzed sample, the application simply opened a webpage for the game “Lifted Dreams.” Meanwhile, the destructive malicious functions continued to operate silently in the background.

Links to the BH Alert Campaign

Specialists successfully linked Octagon to the previous BH Alert campaign, which the Dream Group had previously analyzed. During that specific campaign, attackers utilized themes related to Bahrain’s civil defense. They deployed fraudulent Google Play pages, counterfeit government websites, and a complex multi-stage installation chain. The final payload component contained the identical com.kisa.octagonpanel package. It also utilized port 4444, the exact same keyphrase, and the identical Ward and Guardian mechanisms.

Detecting the Octagon Threat

Alarmingly, Octagon can function flawlessly even when Google Play Protect reports finding no malicious applications on the device. This evasion occurs because a substantial portion of the malware’s capabilities relies entirely on standard, legitimate Android functions. The user must manually grant the installed application access to these powerful features.

To accurately identify a potential infection, iVerify strongly recommends scrutinizing any applications installed from outside the official Google Play Store. Users should be particularly wary of programs requesting access to Accessibility Services, the list of installed applications, unrestricted background operation, and battery optimization exemptions. Additionally, security administrators should actively monitor network traffic for suspicious connections utilizing TCP port 4444. They should also search for characteristic strings like WardAccessibilityService, OctagonBridge, and WARD_GATE_ANSWER. Because server addresses and decoy appearances change frequently, analyzing application behavior provides a far more reliable indicator of infection than relying solely on isolated network addresses.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply