Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware
ID: 565acc80-853e-54ea-982e-ba7b5583f318
STIX ID: report--565acc80-853e-54ea-982e-ba7b5583f318
Feed Name: Zimperium Blog
Zimperium and K7 Security describe "Octagon", a sophisticated multi-stage Android RAT masquerading as Bahrain's "BH Alert" app. Octagon extracts an encrypted payload (disguised as a font), decrypts it (RC4-based) and dynamically loads code via DexClassLoader, abuses Accessibility services to capture keystrokes and UI data, and attempts VPN hijacking to inspect and redirect network traffic; Zimperium reports on-device, ML-driven detection and prevention of the threat prior to public IOC disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
