Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Octagon is an Android theft tool that turns an infected phone into a platform for account takeover.

It can steal login details, watch the screen, and capture verification codes that banks and exchanges use to protect accounts.

It is sold as a service, making financial fraud tools available to more criminals. Victims are lured into installing an Android app outside official stores, often one disguised by an unrelated theme, a fake store page, or a believable public-service message.

Analysts at iVerify identified Octagon in June 2026 and linked it to a Russian-speaking seller known as AndroidKitKat. 

iVerify said in a report shared with Cyber Security News (CSN) that the operation appeared on a Russian-language cybercrime forum on June 1.

Its advertised $1,400 monthly price and ready-made control panel make it notable beyond any one campaign.

Octagon panel overview (Source - iVerify)
Octagon panel overview (Source – iVerify)

Evidence suggests early use, but its focus on wallets, exchanges, banking apps, and messaging services creates a direct path to theft.

Octagon Can Steal SMS One-Time Codes

Octagon abuses Android accessibility features. When a victim enables the requested access, the malware can read screen content, inspect app interfaces, place fake forms over legitimate apps, and let a remote operator control the device.

The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.

Trust Wallet in the panel’s accessibility node tree (Source – iVerify)

Like Crocodilus Android malware analysis, Octagon uses accessibility access and overlay pages against financial apps. The related Lifted Dreams build asks to read, receive, and send SMS messages.

It stores and forwards incoming texts, including one-time passcodes, allowing an attacker to answer an SMS-based login challenge after stealing a password or taking control of a victim’s session.

That turns a single compromised phone into a powerful fraud tool. Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.

Supplied templates include Trust Wallet, Binance, and MEXC, with other wallet and exchange targets visible in the panel.

Sideloaded Apps Enable Fraud

The Android implant connects to a Windows-based control panel. Buyers can check apps and balances, push a tailored overlay, and steer the screen in real time.

This on-device fraud model can work around warnings that might otherwise stop a suspicious web login.

Researchers recovered three related APK samples that share a client design, encrypted control connection, accessibility setup, and overlay assets.

One loaded a harmless-looking launcher page; another revealed a Lifted Dreams visual novel after seeking permissions.

Google Play Protect reporting no harmful apps (Source - iVerify)
Google Play Protect reporting no harmful apps (Source – iVerify)

A related Bahrain operation used fake government and Google Play pages and a four-stage APK chain.

Readers should be wary of unsolicited links and prompts to install files, a risk also seen in fake Play Store delivery, where deceptive pages delivered Android malware.

The malware may keep running even while Google Play Protect reports no harmful apps.

That finding does not invalidate platform protection, but it shows how social engineering and user-approved accessibility access can give a malicious app broad visibility and control after installation.

Install banking and wallet apps only from their official sources, and never grant accessibility access to unfamiliar software.

Treat unexpected requests for SMS, call, battery, or app-install permissions as a warning. If compromise is suspected, disconnect the phone, contact the provider through a trusted route, and reset credentials from a clean device.

Defenders can look for sideloaded apps that combine accessibility, app discovery, foreground execution, wake locks, and battery exclusions.

They should investigate encrypted TCP traffic on port 4444 and hunt for the shared identifiers in the table, rather than depending only on servers or cover pages that operators can replace.

For crypto users, recovery phrases are master keys, not ordinary verification information.

They should never be typed into a pop-up overlay, game-like installer, or unexpected support page. The SparkKitty wallet theft case similarly shows the danger of exposing wallet recovery material to untrusted apps.

Indicators of Compromise (IoCs):-

Type Indicator Description
Threat actor handle AndroidKitKat Handle used by the reported Octagon operator in underground sales material
Underground presence Russian-language cybercrime forums Forums where the operator advertised the service
Package name com.kisa.octagonpanel Shared Android package name across the analyzed APK samples
Default C2 key octagon-default-key-change-me Default passphrase used by the shared client
Control port 4444/tcp TCP port used for the encrypted control connection
SHA-256 APK hash 3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9 Octagon APK sample
SHA-256 APK hash 41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0 BahrDate APK sample
SHA-256 APK hash b7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f Lifted Dreams APK sample
C2 IP address 45.192.12[.]34 Octagon config.json command-and-control server
C2 IP address 45.150.34[.]77 BahrDate config.json command-and-control server
C2 IP address 104.251.180[.]179 Lifted Dreams config.json command-and-control server
Fallback C2 IP address 209.99.187[.]28 Lifted Dreams fallback host when configuration cannot be read
Certificate SHA-256 d472e984c6e8f3d4d7352125ebcc7c3c5609b2afc0f248a2e7028a59f9edc5e7 Octagon signer certificate hash
Cover URL hxxps://www.murlauncher[.]com/fenrir-launcher Hidden WebView cover page in the Octagon APK
Cover URL hxxps://sandbox-adventure[.]com/lifted-dreams/game Victim-facing cover page in the Lifted Dreams APK
Related campaign C2 IP 209.99.184[.]50 C2 linked to the separate BH Alert payload campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

The post Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers appeared first on Cyber Security News.