A malicious Android application has been discovered distributing a devastating four-stage surveillance platform that can harvest sensitive user data, run banking-app overlays, and take full control of infected devices. Dubbed “BH Alert,” this fake emergency alert app is masquerading as an official Bahraini civil-defense application, preying on users’ trust during times of crisis.
Developed by researchers at Dream, a cybersecurity vendor specializing in national defense and critical infrastructure, the BH Alert threat campaign exploits the implicit trust associated with government-provided software. This is particularly concerning given that similar apps have been previously discovered to be Trojanized with malware. In this case, the app’s distribution is thought to be linked to Iranian missile strikes on Bahrain and other Gulf states.
The surveillance platform, known as OctagonPanel, is capable of intercepting SMSs, stealing contacts and credentials, capturing screenshots, running banking-app overlays, and taking full control of infected devices. The malware is distributed through fake Google Play sites that clone official government websites, lending credibility to the malicious application. These sites feature authentic-looking logos, publisher labels, fake reviews, and download counts, making it difficult for users to distinguish between legitimate and fake applications.
Researchers speculate that users are directed to these fake landing pages via smishing links and social media messages, which then lead them to the malicious Google Play page. Once installed, the BH Alert app poses as an official civil-defense application, using bilingual content to impersonate Bahrain Civil Defense and the Ministry of Interior. The app’s setup sequence appears necessary for emergency alerts but actually serves two real goals: installing the payload package and securing privileges needed for persistent surveillance.
The four-stage malware delivery process injects a DEX file installer; installs and launches the initial payload; injects OctagonPanel, along with the Ward framework used for command-and-control, surveillance, and remote operations; and finally establishes an operator-controlled surveillance session. This compromised employee smartphone could potentially be used to bypass multifactor authentication (MFA) protections and gain access to corporate applications.
This threat campaign raises concerns about the vulnerability of Android devices to sophisticated malware attacks. As users increasingly rely on their smartphones for daily activities, it’s essential to remain vigilant against such threats. To protect yourself from similar attacks, consider taking the following precautions: only download apps from trusted sources like Google Play; verify app permissions and reviews before installing; and keep your device’s operating system and security software up-to-date.
Source: Dark Reading — 2026-07-22