logo

Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

ID: 09603c8c-2fbe-5c93-8a84-003ee418e7bb

STIX ID: report--09603c8c-2fbe-5c93-8a84-003ee418e7bb

Feed Name: iVerify Blog

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-14

...
...

Octagon is an Android on-device fraud bot offered as a malware-as-a-service by the Russian-speaking actor AndroidKitKat; the report documents its accessibility-abuse overlays, hidden remote control (VNC), SMS/OTP interception, unlock-pattern capture, balance-reading, persistence mechanisms, and sideload delivery. Analysts recovered three related APKs with shared identifiers (com.kisa.octagonpanel, default C2 key, port 4444), listed C2 IPs and signer hashes, and linked a separate Bahrain-themed BH Alert campaign that used similar artifacts; recommended detection focuses on installation/permission flows, encrypted TCP control on port 4444, and shared client identifiers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.