logo

Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware

ID: 565acc80-853e-54ea-982e-ba7b5583f318

STIX ID: report--565acc80-853e-54ea-982e-ba7b5583f318

Feed Name: Zimperium Blog

Threat Score
72/100

Date Published: 2026-08-04

Date Updated: 2026-08-05

...
...

Zimperium and K7 Security describe "Octagon", a sophisticated multi-stage Android RAT masquerading as Bahrain's "BH Alert" app. Octagon extracts an encrypted payload (disguised as a font), decrypts it (RC4-based) and dynamically loads code via DexClassLoader, abuses Accessibility services to capture keystrokes and UI data, and attempts VPN hijacking to inspect and redirect network traffic; Zimperium reports on-device, ML-driven detection and prevention of the threat prior to public IOC disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.