Categories: Uncategorized

Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers

Octagon is an Android theft tool that turns an infected phone into a platform for account takeover.

It can steal login details, watch the screen, and capture verification codes that banks and exchanges use to protect accounts.

It is sold as a service, making financial fraud tools available to more criminals. Victims are lured into installing an Android app outside official stores, often one disguised by an unrelated theme, a fake store page, or a believable public-service message.

Analysts at iVerify identified Octagon in June 2026 and linked it to a Russian-speaking seller known as AndroidKitKat. 

iVerify said in a report shared with Cyber Security News (CSN) that the operation appeared on a Russian-language cybercrime forum on June 1.

Its advertised $1,400 monthly price and ready-made control panel make it notable beyond any one campaign.

Octagon panel overview (Source – iVerify)

Evidence suggests early use, but its focus on wallets, exchanges, banking apps, and messaging services creates a direct path to theft.

Octagon Can Steal SMS One-Time Codes

Octagon abuses Android accessibility features. When a victim enables the requested access, the malware can read screen content, inspect app interfaces, place fake forms over legitimate apps, and let a remote operator control the device.

The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.

Trust Wallet in the panel’s accessibility node tree (Source – iVerify)

Like Crocodilus Android malware analysis, Octagon uses accessibility access and overlay pages against financial apps. The related Lifted Dreams build asks to read, receive, and send SMS messages.

It stores and forwards incoming texts, including one-time passcodes, allowing an attacker to answer an SMS-based login challenge after stealing a password or taking control of a victim’s session.

That turns a single compromised phone into a powerful fraud tool. Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.

Supplied templates include Trust Wallet, Binance, and MEXC, with other wallet and exchange targets visible in the panel.

Sideloaded Apps Enable Fraud

The Android implant connects to a Windows-based control panel. Buyers can check apps and balances, push a tailored overlay, and steer the screen in real time.

This on-device fraud model can work around warnings that might otherwise stop a suspicious web login.

Researchers recovered three related APK samples that share a client design, encrypted control connection, accessibility setup, and overlay assets.

One loaded a harmless-looking launcher page; another revealed a Lifted Dreams visual novel after seeking permissions.

Google Play Protect reporting no harmful apps (Source – iVerify)

A related Bahrain operation used fake government and Google Play pages and a four-stage APK chain.

Readers should be wary of unsolicited links and prompts to install files, a risk also seen in fake Play Store delivery, where deceptive pages delivered Android malware.

The malware may keep running even while Google Play Protect reports no harmful apps.

That finding does not invalidate platform protection, but it shows how social engineering and user-approved accessibility access can give a malicious app broad visibility and control after installation.

Install banking and wallet apps only from their official sources, and never grant accessibility access to unfamiliar software.

Treat unexpected requests for SMS, call, battery, or app-install permissions as a warning. If compromise is suspected, disconnect the phone, contact the provider through a trusted route, and reset credentials from a clean device.

Defenders can look for sideloaded apps that combine accessibility, app discovery, foreground execution, wake locks, and battery exclusions.

They should investigate encrypted TCP traffic on port 4444 and hunt for the shared identifiers in the table, rather than depending only on servers or cover pages that operators can replace.

For crypto users, recovery phrases are master keys, not ordinary verification information.

They should never be typed into a pop-up overlay, game-like installer, or unexpected support page. The SparkKitty wallet theft case similarly shows the danger of exposing wallet recovery material to untrusted apps.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Threat actor handleAndroidKitKatHandle used by the reported Octagon operator in underground sales material
Underground presenceRussian-language cybercrime forumsForums where the operator advertised the service
Package namecom.kisa.octagonpanelShared Android package name across the analyzed APK samples
Default C2 keyoctagon-default-key-change-meDefault passphrase used by the shared client
Control port4444/tcpTCP port used for the encrypted control connection
SHA-256 APK hash3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9Octagon APK sample
SHA-256 APK hash41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0BahrDate APK sample
SHA-256 APK hashb7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4fLifted Dreams APK sample
C2 IP address45.192.12[.]34Octagon config.json command-and-control server
C2 IP address45.150.34[.]77BahrDate config.json command-and-control server
C2 IP address104.251.180[.]179Lifted Dreams config.json command-and-control server
Fallback C2 IP address209.99.187[.]28Lifted Dreams fallback host when configuration cannot be read
Certificate SHA-256d472e984c6e8f3d4d7352125ebcc7c3c5609b2afc0f248a2e7028a59f9edc5e7Octagon signer certificate hash
Cover URLhxxps://www.murlauncher[.]com/fenrir-launcherHidden WebView cover page in the Octagon APK
Cover URLhxxps://sandbox-adventure[.]com/lifted-dreams/gameVictim-facing cover page in the Lifted Dreams APK
Related campaign C2 IP209.99.184[.]50C2 linked to the separate BH Alert payload campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago