Octagon is an Android theft tool that turns an infected phone into a platform for account takeover.
It can steal login details, watch the screen, and capture verification codes that banks and exchanges use to protect accounts.
It is sold as a service, making financial fraud tools available to more criminals. Victims are lured into installing an Android app outside official stores, often one disguised by an unrelated theme, a fake store page, or a believable public-service message.
Analysts at iVerify identified Octagon in June 2026 and linked it to a Russian-speaking seller known as AndroidKitKat.
iVerify said in a report shared with Cyber Security News (CSN) that the operation appeared on a Russian-language cybercrime forum on June 1.
Its advertised $1,400 monthly price and ready-made control panel make it notable beyond any one campaign.
Evidence suggests early use, but its focus on wallets, exchanges, banking apps, and messaging services creates a direct path to theft.
Octagon abuses Android accessibility features. When a victim enables the requested access, the malware can read screen content, inspect app interfaces, place fake forms over legitimate apps, and let a remote operator control the device.
The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.
Like Crocodilus Android malware analysis, Octagon uses accessibility access and overlay pages against financial apps. The related Lifted Dreams build asks to read, receive, and send SMS messages.
It stores and forwards incoming texts, including one-time passcodes, allowing an attacker to answer an SMS-based login challenge after stealing a password or taking control of a victim’s session.
That turns a single compromised phone into a powerful fraud tool. Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.
Supplied templates include Trust Wallet, Binance, and MEXC, with other wallet and exchange targets visible in the panel.
The Android implant connects to a Windows-based control panel. Buyers can check apps and balances, push a tailored overlay, and steer the screen in real time.
This on-device fraud model can work around warnings that might otherwise stop a suspicious web login.
Researchers recovered three related APK samples that share a client design, encrypted control connection, accessibility setup, and overlay assets.
One loaded a harmless-looking launcher page; another revealed a Lifted Dreams visual novel after seeking permissions.
A related Bahrain operation used fake government and Google Play pages and a four-stage APK chain.
Readers should be wary of unsolicited links and prompts to install files, a risk also seen in fake Play Store delivery, where deceptive pages delivered Android malware.
The malware may keep running even while Google Play Protect reports no harmful apps.
That finding does not invalidate platform protection, but it shows how social engineering and user-approved accessibility access can give a malicious app broad visibility and control after installation.
Install banking and wallet apps only from their official sources, and never grant accessibility access to unfamiliar software.
Treat unexpected requests for SMS, call, battery, or app-install permissions as a warning. If compromise is suspected, disconnect the phone, contact the provider through a trusted route, and reset credentials from a clean device.
Defenders can look for sideloaded apps that combine accessibility, app discovery, foreground execution, wake locks, and battery exclusions.
They should investigate encrypted TCP traffic on port 4444 and hunt for the shared identifiers in the table, rather than depending only on servers or cover pages that operators can replace.
For crypto users, recovery phrases are master keys, not ordinary verification information.
They should never be typed into a pop-up overlay, game-like installer, or unexpected support page. The SparkKitty wallet theft case similarly shows the danger of exposing wallet recovery material to untrusted apps.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Threat actor handle | AndroidKitKat | Handle used by the reported Octagon operator in underground sales material |
| Underground presence | Russian-language cybercrime forums | Forums where the operator advertised the service |
| Package name | com.kisa.octagonpanel | Shared Android package name across the analyzed APK samples |
| Default C2 key | octagon-default-key-change-me | Default passphrase used by the shared client |
| Control port | 4444/tcp | TCP port used for the encrypted control connection |
| SHA-256 APK hash | 3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9 | Octagon APK sample |
| SHA-256 APK hash | 41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0 | BahrDate APK sample |
| SHA-256 APK hash | b7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f | Lifted Dreams APK sample |
| C2 IP address | 45.192.12[.]34 | Octagon config.json command-and-control server |
| C2 IP address | 45.150.34[.]77 | BahrDate config.json command-and-control server |
| C2 IP address | 104.251.180[.]179 | Lifted Dreams config.json command-and-control server |
| Fallback C2 IP address | 209.99.187[.]28 | Lifted Dreams fallback host when configuration cannot be read |
| Certificate SHA-256 | d472e984c6e8f3d4d7352125ebcc7c3c5609b2afc0f248a2e7028a59f9edc5e7 | Octagon signer certificate hash |
| Cover URL | hxxps://www.murlauncher[.]com/fenrir-launcher | Hidden WebView cover page in the Octagon APK |
| Cover URL | hxxps://sandbox-adventure[.]com/lifted-dreams/game | Victim-facing cover page in the Lifted Dreams APK |
| Related campaign C2 IP | 209.99.184[.]50 | C2 linked to the separate BH Alert payload campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…