Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
ID: 8a9956bf-3ba6-5c14-9a5f-f395320e1c18
STIX ID: report--8a9956bf-3ba6-5c14-9a5f-f395320e1c18
Feed Name: cybersecurityNews.com
Researchers from DreamGroup uncovered a sophisticated Android malware campaign masquerading as a Bahrain Civil Defense "BH Alert" app that uses fake Google Play listings and spoofed government portals to distribute a four‑stage RAT (Ematterassist → com.kit.kitty → Hvoicemanual → com.kisa.octagonpanel/Ward). The malware harvests lockscreen PINs, SMS/OTP, banking credentials, captures screenshots, and exfiltrates contacts and call logs while using Accessibility Services, fake VPN behavior, persistence mechanisms, and anti‑analysis techniques (RC4 payloads in .ttf files, runtime injection). Defenders are advised to install only from official stores, verify developers, avoid unsolicited links, and scrutinize Accessibility/SMS permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
