Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
AI Analysis
Technical Summary
Octagon is an Android fraud bot sold as malware-as-a-service by the Russian-speaking actor AndroidKitKat for $1,400 monthly. It employs accessibility overlays to capture user input, hidden VNC for remote device control, SMS interception, unlock-pattern capture, and balance reading to target cryptocurrency wallets, exchanges, and banking apps. The malware is distributed through sideloaded APKs that bypass Android's Restricted Settings protections. Once installed, it connects infected devices to a Windows-based command-and-control panel where operators monitor applications, read device screens, and control devices remotely. Persistence is maintained through various mechanisms, and the malware is designed to appear benign to security scans. Three APK samples have been recovered, including those using the Lifted Dreams game and Bahrain government-themed lures. Credential theft is facilitated via HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account takeover.
Potential Impact
Octagon enables attackers to remotely control infected Android devices, intercept SMS messages, capture unlock patterns, and steal credentials from targeted cryptocurrency wallets, exchanges, and banking applications. This can lead to unauthorized access to financial accounts, theft of cryptocurrency assets, and compromise of messaging apps. The malware's persistence and stealth capabilities increase the risk of prolonged undetected compromise on infected devices.
Mitigation Recommendations
No official patch or remediation is currently available as this is malware distributed via sideloaded APKs. Users should avoid installing applications from untrusted sources and sideloaded APKs. Security teams should monitor for indicators of compromise such as the provided IP addresses, hashes, and URLs associated with Octagon. Employ mobile threat defense solutions capable of detecting accessibility abuse and overlay attacks. Users should be cautious of phishing lures mimicking legitimate games or government sites. Regularly updating devices and apps, and using multi-factor authentication on financial and messaging apps can reduce risk. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Indicators of Compromise
- ip: 45.192.12.34
- ip: 209.99.184.50
- ip: 209.99.187.28
- hash: 3530b1600e059468e585d48482bb2f37
- hash: 41d922a220ac28a4af8cbed3ffff517b
- hash: 471bcf065c6ed44282c5776ee78bc6d0
- hash: b7e9072e5bda17e0c68db01010658481
- hash: d472e984c6e8f3d4d7352125ebcc7c3c
- hash: 54bccb0626f91a85d70803f4ecadd5cbd303f5e9
- hash: 3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9
- hash: 41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0
- hash: b7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f
- ip: 104.251.180.179
- ip: 45.150.34.77
- url: http://www.murlauncher.com/fenrir-launcher
- url: https://sandbox-adventure.com/lifted-dreams/game
- url: https://www.murlauncher.com/fenrir-launcher
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
Description
In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Octagon is an Android fraud bot sold as malware-as-a-service by the Russian-speaking actor AndroidKitKat for $1,400 monthly. It employs accessibility overlays to capture user input, hidden VNC for remote device control, SMS interception, unlock-pattern capture, and balance reading to target cryptocurrency wallets, exchanges, and banking apps. The malware is distributed through sideloaded APKs that bypass Android's Restricted Settings protections. Once installed, it connects infected devices to a Windows-based command-and-control panel where operators monitor applications, read device screens, and control devices remotely. Persistence is maintained through various mechanisms, and the malware is designed to appear benign to security scans. Three APK samples have been recovered, including those using the Lifted Dreams game and Bahrain government-themed lures. Credential theft is facilitated via HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account takeover.
Potential Impact
Octagon enables attackers to remotely control infected Android devices, intercept SMS messages, capture unlock patterns, and steal credentials from targeted cryptocurrency wallets, exchanges, and banking applications. This can lead to unauthorized access to financial accounts, theft of cryptocurrency assets, and compromise of messaging apps. The malware's persistence and stealth capabilities increase the risk of prolonged undetected compromise on infected devices.
Defensive Guidance
No official patch or remediation is currently available as this is malware distributed via sideloaded APKs. Users should avoid installing applications from untrusted sources and sideloaded APKs. Security teams should monitor for indicators of compromise such as the provided IP addresses, hashes, and URLs associated with Octagon. Employ mobile threat defense solutions capable of detecting accessibility abuse and overlay attacks. Users should be cautious of phishing lures mimicking legitimate games or government sites. Regularly updating devices and apps, and using multi-factor authentication on financial and messaging apps can reduce risk. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps"]
- Adversary
- AndroidKitKat
- Pulse Id
- 6a8474eb4f130dfa41887e40
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip45.192.12.34 | — | |
ip209.99.184.50 | — | |
ip209.99.187.28 | — | |
ip104.251.180.179 | — | |
ip45.150.34.77 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash3530b1600e059468e585d48482bb2f37 | — | |
hash41d922a220ac28a4af8cbed3ffff517b | — | |
hash471bcf065c6ed44282c5776ee78bc6d0 | — | |
hashb7e9072e5bda17e0c68db01010658481 | — | |
hashd472e984c6e8f3d4d7352125ebcc7c3c | — | |
hash54bccb0626f91a85d70803f4ecadd5cbd303f5e9 | — | |
hash3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9 | — | |
hash41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0 | — | |
hashb7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://www.murlauncher.com/fenrir-launcher | — | |
urlhttps://sandbox-adventure.com/lifted-dreams/game | — | |
urlhttps://www.murlauncher.com/fenrir-launcher | — |
Threat ID: 6a84b755c6e8be0332ab733c
Added to database: 08/18/2026, 19:49:41 UTC
Last enriched: 09/17/2026, 22:01:56 UTC
Last updated: 10/04/2026, 00:39:34 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.