Malware News K7 Labs details Octagon’s multi-stage Android threat that uses dynamic payload loading, VPN and Accessibility abuse, local data storage....

Khushal

Level 16
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
773
5,105
1,469
Unlike traditional Android Remote Access Trojan (RAT), Android Octagon employs a multi-stage design that dynamically loads encrypted DEX and JAR payloads while abusing VPN and Accessibility services to maintain persistence and steal sensitive information.

During our investigation, the campaign primarily targeted users in Bahrain by impersonating the official BH Alert emergency application.

 
Important warning about fake BH Alert applications

The described campaign is a good example of why Android users should avoid installing emergency or government applications from links received through SMS, social media, email, or unofficial websites. The use of Accessibility and VPN services is particularly concerning because these permissions can provide extensive device visibility and control.

Users should:

  • Install BH Alert only through an official government website or the verified Google Play listing.
  • Check the developer name, download count, reviews, update history, and requested permissions before installing.
  • Avoid granting Accessibility, VPN, Device Administrator, SMS, or notification access unless the application’s function clearly requires it.
  • Uninstall suspicious applications and revoke their permissions if they were installed from an untrusted source.
  • Run a scan with reputable mobile security software and review accounts for unauthorized activity.
  • Change important passwords from a separate, trusted device if credentials or banking information may have been exposed.

A VPN permission by itself does not prove that an application is malicious, but it allows an application to route device traffic and should be treated cautiously when combined with sideloading, Accessibility access, encrypted payload loading, or requests to disable security protections.

The article is useful technical background, but a definitive assessment of any particular APK still requires examining that exact sample and its hashes. Suspicious files should not be installed for testing on a personal device; submit them to a reputable analysis service such as VirusTotal and wait for additional expert analysis.