Octagon Malware-as-a-Service Platform Targets Android Banking Apps and Crypto Wallets for $1400 Monthly Subscription
Researchers from iVerify have discovered a previously unknown malware platform called Octagon designed for attacks on Android banking applications and cryptocurrency wallets. The toolkit is distributed under a malware-as-a-service model, with a Russian-speaking seller using the handle AndroidKitKat charging $1400 per month for access.
Octagon first appeared on a cybercrime forum on 1 June 2026, and by 29 June the author had already announced version 1.2. Subscribers receive a ready-made control panel capable of capturing accounts at banks, cryptocurrency exchanges, messengers, and wallets. Infection begins when the victim installs an APK file disguised as a harmless application.
After installation, the program requests activation of Android Accessibility Services. Once granted, the trojan can read on-screen interface elements, press buttons, enter text, and perform system actions directly on the victim’s device. Because operations occur on the compromised smartphone itself, banks and exchanges see the legitimate IP address, device fingerprint, installed applications, and an already authenticated session, making the activity appear normal to anti-fraud systems.
The platform supports hidden remote screen control similar to VNC, captures screenshots, launches applications, and simulates touches. It overlays phishing windows on top of interfaces belonging to Trust Wallet, Binance, MEXC, and other services to harvest passwords, PIN codes, and seed phrases. A dedicated module intercepts SMS messages containing one-time codes, transaction confirmations, and account-recovery links. Attackers can even spoof the system lock screen to steal the device’s graphical pattern or password.
Investigators identified three related builds: Octagon, Lifted Dreams, and BahrDate. In one variant, after permissions are granted, a visual novel is displayed to the user while the spyware continues operating in the background. Security experts advise users to avoid installing APK files from unknown sources and to refrain from granting Accessibility Services or SMS permissions to untrusted applications.
Related articles
BTMOB Platform Turns Android Banking Trojan into Customizable Fraud Campaign Constructor
Researchers at QuimeraX have uncovered BTMOB, a platform that evolved from a banking trojan into a full-featured builder for fraudulent Android campaigns. The service allows clients without development skills to select an app name, icon, command-and-control server, permissions, and social-engineering lure, after which the system automatically compiles a ready-to-use APK. The package includes an Android payload, dropper, VB.NET control panel, PHP and MySQL backend, and build tools that enable rapid production of localized copies of streaming services, banking protection modules, parcel trackers, and social networks. One BTMOB 2.5 variant was distributed via a phishing site mimicking the Turkish iNat TV service, while Brazilian operators created fake Google Play pages impersonating Nubank, TikTok, and the government portal Gov.BR. After installation, the trojan requests accessibility permissions and, once granted, grants operators near-complete device control including screen viewing, keystroke capture, audio recording, and real-time WebSocket interaction that lets attackers perform actions directly on the victim’s device. Analysts link BTMOB to the SpySolr family and earlier commercial RATs CypherRAT and CraxsRAT, which had already attracted more than 100 licensees.
Dysphoria Botnet Compromises Nearly 300,000 Devices for DDoS Attacks and Residential Proxy Services
The Dysphoria botnet has infected approximately 296,000 devices, including routers, IP cameras, gateways, and embedded Linux systems. Researchers first observed the threat in the first quarter of 2026, noting rapid evolution from the jackskid and fbot families. The infrastructure is primarily used for DDoS attacks but has expanded to offer residential proxy capabilities. Infection occurs through brute-force attacks on Telnet and SSH services with weak credentials, as well as known remote code execution vulnerabilities in IoT equipment. A key technical advancement involves the use of Ethereum and Solana blockchain domains for command-and-control infrastructure, making takedowns significantly harder. Compromised devices can also function as relays by leveraging UPnP to expose ports and hide criminal traffic origins. Operators advertise attack capacity of up to 4 Tbps and sell DDoS services in structured commercial packages targeting internet services and gaming platforms worldwide.
TRON, Aptos and BSC in One Infection Chain: JavaScript Loader Linked to ChainVeil Campaign
Researchers at Checkmarx examined the ChainVeil campaign that used npm packages to distribute multi-stage JavaScript loaders. A newly discovered sample appeared in a GitHub repository recommended by an AI agent, where the file navigation.js contained an obfuscated loader that matched the campaign's techniques. The loader retrieves encrypted payloads from TRON, falls back to Aptos, and then uses the extracted data as a BSC transaction identifier to fetch the next stage. C2 infrastructure and final RAT functionality aligned exactly with previously published indicators, except for the campaign identifier A9-0554-3 instead of the A6-* markers seen in npm samples. Git history showed the malicious code was inserted via a merge commit on 29 March 2026, months before the first known npm packages appeared in May. The findings indicate that npm was never the only distribution channel for ChainVeil and that the campaign's blockchain-based delivery mechanism has been active since at least early 2025.
Malinsure Cybercrime Group Deploys SafeMostSSH Backdoor via Phishing Lures Mimicking Russian Insurance Updates
Researchers from F6 identified a previously unknown cybercrime cluster named Malinsure that has been active since at least July 2026. The group distributes phishing emails containing PDF lures themed around voluntary medical insurance (DMS) discounts and updates from Russian insurance companies. Victims are tricked into downloading RAR or ZIP archives that abuse legitimate Microsoft binaries such as winword.exe and powerpnt.exe through DLL side-loading to execute the custom SafeMostSSH backdoor. The malware establishes a persistent reverse SSH tunnel to attacker-controlled servers and retrieves fresh C2 addresses from public posts on vc.ru by decoding fake PNG links. Additional delivery vectors include HTML and SHTML files that decode and drop archives containing the same payload components. Targets appear to include insurance, finance, and fuel-energy sector organizations, with infrastructure also referencing gosuslugi.email and minfin.support domains.