Android RAT Survives Reboots Using Watchdog Services and Boot Receivers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Android users are facing a new remote-access threat that hides behind a fake emergency alert application.

The malware, called Octagon, poses as Bahrain’s BH Alert service and leads victims through a convincing setup process designed to win dangerous permissions.

The campaign takes advantage of public concern during a period of regional tension. Victims are directed to phishing pages and download an Android package outside official stores, where a familiar-looking app icon and emergency language make the scam appear legitimate.

K7 Security Labs identified the malware as a layered Android threat that can steal device unlock details, SMS messages, banking information and other private data.

Its design makes a restart far less useful than users may expect, because components can resume the operation after the phone comes back online.

K7 Security Labs said in a report shared with Cyber Security News (CSN) that the campaign primarily targeted users in Bahrain by impersonating the official emergency application.

FakeBH Alert application (Source – K7 Security Labs)

The case also shows why official-looking pages, urgent notices and permission prompts should be treated with care.

Android RAT Survives Reboots

Octagon begins with BH-Alert.apk, which requests access in seven steps before installing a second component.

The first app hides executable code inside an encrypted file named ZfChs.ttf, decrypts it on the device, and loads it only when needed. That approach limits what a basic scan can see at first.

The malware then installs a child application known as OctagonPanel and creates another code file at runtime.

Its services operate in the background, while watchdog processes monitor one another and restart a partner if it is stopped. A reboot does not necessarily end the intrusion because boot receivers can launch the malware again when Android starts.

Seven-step setup process (Source – K7 Security Labs)

This persistence method belongs to a growing pattern. A malicious Android TV compromise also showed how a boot receiver can initialize hidden activity, while a recent Android persistence case used BOOT_COMPLETED to resume a harmful process after restart.

Octagon adds a fake Android account, OctagonPanel, and schedules synchronization every 30 minutes.

The routine can wake the malware periodically or on demand, letting it reconnect with its command server and preserve settings that include removal resistance. This makes cleaning an infected phone more difficult than simply closing the visible app.

Investigators also found that Octagon stores configuration, phishing templates and intercepted messages in a local SQLite database.

That cache allows collection to continue through temporary loss of connectivity and lets the operator synchronize stolen information later. Data is protected through encrypted communication on a non-standard port.

Credential theft extends the risk

Once active, Octagon asks the victim to enable Accessibility Service and a VPN connection. Accessibility is meant to help people use phones, but here it records lock-screen PINs, passwords and patterns as they are entered.

The malware can retain a history of captured credentials in local storage before sending information onward.

The VPN request is equally deceptive. Rather than protecting the victim, it can route traffic through an attacker-controlled tunnel, helping intercept or redirect sensitive activity.

A selected list of applications remains outside the tunnel so the phone continues to appear normal, reducing the chance that a victim notices the interference.

The child app also gathers SMS messages, contacts, call records, screenshots and configuration data, and can display phishing pages over targeted applications.

Request to install app from unknown source (Source – K7 Security Labs)

These capabilities resemble those documented in DroidBot banking malware analysis, where Accessibility abuse supported keylogging and screen monitoring, and in the RedHook RAT persistence report, which described paired services that relaunch each other.

Users should avoid installing software from links in messages, social posts or unverified emergency pages.

Undefined Class Names in AndroidManifest.xml (Source – K7 Security Labs)

They should install apps only from official stores, check the developer name, keep Android updated, and be especially cautious when an app requests Accessibility, VPN, SMS or permission to install other apps.

Anyone who installed BH Alert from an unofficial source should remove it, review account activity and change important credentials from a trusted device.

Indicators of Compromise (IoCs):-

Type Indicator Description
Package name com.kit.kitty Initial malicious application package
File hash 9694294addbe58be93ddbb6cabc499ce Hash associated with com.kit.kitty
Package name com.kisa.octagonpanel Child Android RAT package
File hash 58330aaf1f533e9fe03b6355c60347b4 Hash associated with com.kisa.octagonpanel
C2 server 209.99.184.50:4444 Command-and-control server
URL https://download.alertbh.info/BH-Alert.apk Malicious APK download location
URL https://bh-alert.com/assets/BH-Alert.apk Malicious APK download location
URL https://playgoogle.bh-alert.com Phishing infrastructure URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN