BoletimSecAugust 4, 2026🇵🇹Translated from Portuguese

Octagon Android RAT Poses as Bahrain Emergency Alert App to Steal Credentials and Establish Persistent Surveillance

A remote access trojan for Android called Octagon is impersonating the official emergency alerts application from Bahrain to seize control of devices and exfiltrate sensitive information.

The attack starts when users download the file BH-Alert.apk from phishing pages. The application mimics legitimate services and walks victims through seven separate steps to obtain dangerous permissions. The first component stores part of its code in encrypted form inside a file that uses a font extension. This content is decrypted and loaded only during runtime, making static analysis significantly more difficult.

After initial execution, the malware installs a second application named OctagonPanel. Dedicated surveillance services continuously monitor one another and automatically restart any components that are killed. Boot receivers ensure the threat reactivates after the device is powered on.

Octagon further creates a fake account on the Android system and schedules synchronization tasks every 30 minutes. This mechanism wakes the malware, fetches updated configuration data, and re-establishes communication with the command-and-control server.

By abusing the Accessibility Service, the threat records PINs, passwords, and unlock patterns. The 200 most recent entries can remain stored on the device before being transmitted. The RAT also collects SMS messages, contacts, call logs, and screenshots while displaying fake overlay pages for other applications. A VPN controlled by the attackers can intercept or redirect the victim’s network traffic.

Related articles

HabrMalware & Botnets

Distributed Crawler Poses as Human Visitor to Evade Analytics and Ad Filters

A detailed investigation revealed a sophisticated distributed crawler that successfully mimicked legitimate human browsing behavior across multiple unrelated websites. The crawler generated realistic events in Google Analytics while avoiding ad script loading and resource chains that would confirm genuine user sessions. Server logs showed consistent patterns of fake search engine referrers, internal navigation with fabricated Referer headers, and selective requests limited mostly to images returning 404 errors. Analysts built a graph-based detection system that correlated events across sites to expose the coordinated activity despite individual requests appearing benign. The campaign rotated browser signatures and IP addresses frequently, making single-site rate limiting ineffective. The case demonstrates how modern crawlers can exploit Measurement Protocol and incomplete bot detection to consume server resources without contributing to revenue.

HabrMalware & Botnets

Comprehensive Collection of Malware Analysis and Development Books Released for Security Researchers

A detailed roundup of professional literature covering malware development, reverse engineering, and defensive analysis has been published. The selection includes resources focused on Windows, macOS, and Android platforms. Key titles address practical techniques for building and dissecting malicious software, evasion methods, and forensic investigation. Books such as MalDev Academy and Practical Malware Analysis provide hands-on training with real-world samples and laboratory exercises. Additional volumes explore macOS-specific threats and Android malware detection using machine learning. The compilation aims to support both red team practitioners and malware analysts in deepening their technical expertise.

HabrMalware & Botnets

Bots Now Form Over Half of Global Internet Traffic in 2025, Driving API Attacks and Business Metric Distortion

Automated clients generated more than 50% of analyzed internet traffic in 2025, with malicious bots responsible for 40% of the total volume. AI-enabled automation attacks increased 12.5 times year-over-year, while daily API attacks rose 113% according to Akamai data. Simple scripts still dominate volume at 59% of bot traffic, yet sophisticated botnets exceeding 4.5 million devices now distribute activity across residential proxies and compromised endpoints. Credential stuffing, scraping, and transaction abuse continue to target business logic rather than software vulnerabilities, distorting analytics, inflating infrastructure costs, and degrading user experience. Cloudflare reports that 20% of verified bot traffic now comes from AI crawlers, blurring lines between beneficial and harmful automation. Organizations must classify bots by intent, delegation, and business impact instead of relying on IP reputation or single signals such as User-Agent strings.

AntiMalwareMalware & Botnets

Astaroth Trojan Hijacks WhatsApp Web Sessions to Spread Banking Malware to Contacts

The operators of the Astaroth banking Trojan, also known as Guildma, have added a new module that turns infected Windows systems into automated spam bots for WhatsApp Web. The malware copies browser profiles from Chrome or Edge, launches a legitimate WebDriver instance, and connects to an already authenticated WhatsApp Web session using the WPPConnect/WA-JS library. Once active, the bot scans the victim's contact list and sends each recipient a personalized greeting, a ZIP archive containing the Astaroth loader, and a closing message, all generated with randomized phrasing to evade detection. The technique leverages the trust users place in messages from known contacts, significantly increasing the likelihood of successful infection. Researchers at CrowdStrike note code similarities with tools used by other Latin American groups, including Vareg, suggesting shared development or active exchange of components. Indicators of compromise include PowerShell downloads of WebDriver, creation of ChromeAuto_ folders in C:\Users\Public\Temp, headless Chromium execution, and network activity tied to WPPConnect components.