logo

Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials

ID: 8a9956bf-3ba6-5c14-9a5f-f395320e1c18

STIX ID: report--8a9956bf-3ba6-5c14-9a5f-f395320e1c18

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Guru Baran

...
...

Researchers from DreamGroup uncovered a sophisticated Android malware campaign masquerading as a Bahrain Civil Defense "BH Alert" app that uses fake Google Play listings and spoofed government portals to distribute a four‑stage RAT (Ematterassist → com.kit.kitty → Hvoicemanual → com.kisa.octagonpanel/Ward). The malware harvests lockscreen PINs, SMS/OTP, banking credentials, captures screenshots, and exfiltrates contacts and call logs while using Accessibility Services, fake VPN behavior, persistence mechanisms, and anti‑analysis techniques (RC4 payloads in .ttf files, runtime injection). Defenders are advised to install only from official stores, verify developers, avoid unsolicited links, and scrutinize Accessibility/SMS permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.