ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
A fake Android app pretending to be Bahrain's official civil-defense alert app actually spies on the phone it is installed. It can read text messages, steal login screens, watch the screen, and let an attacker take remote control of the device.
- Report priority
- Critical
- Targets
- Android
How it works
Attackers built copycat websites that clone the Google Play Store and real Bahraini government pages, complete with a fake install animation, then get people to download the fake app there instead of from the real store.
What to do
Check that any civil-defense or emergency-alert app on your phone was installed directly from the official Google Play Store listing, not from a link in a message, search ad, or a copycat website. If you installed BH Alert from anywhere else, assume it may be the fake OctagonPanel version.
Uninstall the app immediately if it did not come from the official Play Store listing, run a reputable mobile security scan, and change passwords and banking logins from a separate, trusted device since the malware can show fake bank overlay screens.
Technical details
A resident in Bahrain searches for the official BH Alert emergency siren app and lands on a cloned site made to look like Google Play. They download and install what appears to be the real app, watching a fake install animation play out. In the background the app installs the OctagonPanel malware, which then harvests lockscreen credentials, SMS messages and one-time codes, contacts and screenshots, and shows fake banking-app login screens to steal credentials.
Security firm Dream disclosed a fake Android app impersonating Bahrain's official 'BH Alert' civil-defense siren app. It is distributed through look-alike domains that clone the Google Play Store and official Bahraini government sites, using fake install animations and ad-tracking pixels to appear legitimate. Once installed it deploys a malware payload called OctagonPanel, described as a four-stage surveillance platform capable of harvesting lockscreen credentials, SMS messages and one-time passcodes, contacts, and screenshots, running fake banking-app overlays, and taking full remote control of the device.
It relies on social engineering and abuse of legitimate Android permissions rather than a software vulnerability. Dream previously found a similar trojanized clone of Israel's 'Red Alert' app.
References
- msrc.microsoft.com · CVE-2026-50522 Patch Vendor Advisory
- nvd.nist.gov · CVE-2026-50522 vdb entry
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- thehackernews.com · unc6671-vishing-attacks-target-personal.html TheHackerNews
- thehackernews.com · deadlock-ransomware-uses-polygon-smart.html TheHackerNews
- securityonline.info · unc6671-vishing-extortion-rebrand SecurityOnline
- neuracybintel.com · levi-strauss-confirms-social-engineering-attack-that-allowed-hackers-to-steal-corporate-data-from-employee-computers NeuraCybIntel
- neuracybintel.com · rising-sextortion-scams-exploit-massive-data-leaks-from-shinyhunters-group NeuraCybIntel