Fake Bahrain Alert App Deploys Android Surveillance Malware
ID: e64af7a1-e85d-5745-8787-a4d4a959abfc
STIX ID: report--e64af7a1-e85d-5745-8787-a4d4a959abfc
Feed Name: Dark Reading
Researchers reported an active campaign distributing a malicious Android app, "BH Alert," masquerading as a Bahraini emergency-alert application via cloned Play Store and government sites; the four-stage payload deploys OctagonPanel and Ward frameworks to perform persistent surveillance, SMS and credential theft, banking-app overlays, screenshots, and remote control, with potential to bypass MFA and affect corporate access. Defenders are advised to use MDM to block sideloads and network monitoring to detect a distinctive ~5-second C2 heartbeat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
