Fake Bahrain Civil Defense App Distributes Advanced Surveillance Malware
ID: e5d9d357-5f07-5f43-a31b-b33eeac7c260
STIX ID: report--e5d9d357-5f07-5f43-a31b-b33eeac7c260
Feed Name: ThreatCluster
A malicious Android app masquerading as a Bahrain civil defense alert tool is actively targeting users in Bahrain and the Gulf, using fake Google Play listings and government branding to increase installations. The app deploys a sophisticated four-stage surveillance malware that harvests lockscreen credentials, SMS messages, and provides remote access; distribution is via phishing links, smishing, and impersonated government websites. The campaign is ongoing and believed to be linked to advanced persistent threat actors (potentially Russian-speaking), exploiting regional tensions to maximize social-engineering effectiveness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
