Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

0
Medium
Published: 08/18/2026 (08/18/2026, 15:06:19 UTC)
Source: AlienVault OTX General

Description

Octagon is a newly identified Android malware-as-a-service bot discovered in June 2026, targeting cryptocurrency wallets, exchanges, and banking applications. It uses accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading to steal credentials and control infected devices remotely. Distributed via sideloaded APKs bypassing restricted settings, Octagon connects devices to a Windows command-and-control panel for real-time monitoring and manipulation. The malware maintains persistence through multiple mechanisms and evades detection by appearing benign to security scans. It has been observed using lures such as the Lifted Dreams game and Bahrain government-themed bait. Octagon specifically targets apps like Trust Wallet, Binance, MEXC, MetaMask, Telegram, and WhatsApp to facilitate cryptocurrency theft and account takeover.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 20:24:16 UTC

Technical Analysis

Octagon is an Android fraud bot sold as malware-as-a-service by the Russian-speaking actor AndroidKitKat for $1,400 monthly. It employs multiple advanced techniques including accessibility overlays to capture user input, hidden VNC for remote device control, SMS interception, unlock-pattern capture, and balance reading to target cryptocurrency wallets, exchanges, and banking apps. The malware is distributed through sideloaded APKs that bypass Android's Restricted Settings protections. Once installed, it connects infected devices to a Windows-based command-and-control panel where operators can monitor applications, read device screens, and control devices remotely. Persistence is maintained through various mechanisms, and the malware is designed to appear benign to security scans. Three APK samples have been recovered, including those using the Lifted Dreams game and Bahrain government-themed lures. Credential theft is facilitated via HTML WebView overlays targeting popular crypto wallets and messaging apps, enabling theft of cryptocurrency and account takeover.

Potential Impact

Octagon enables attackers to remotely control infected Android devices, intercept SMS messages, capture unlock patterns, and steal credentials from targeted cryptocurrency wallets, exchanges, and banking applications. This can lead to unauthorized access to financial accounts, theft of cryptocurrency assets, and compromise of messaging apps. The malware's persistence and stealth capabilities increase the risk of prolonged undetected compromise on infected devices.

Defensive Guidance

No official patch or remediation is currently available as this is malware distributed via sideloaded APKs. Users should avoid installing applications from untrusted sources and sideloaded APKs. Security teams should monitor for indicators of compromise such as the provided IP addresses, hashes, and URLs associated with Octagon. Employ mobile threat defense solutions capable of detecting accessibility abuse and overlay attacks. Users should be cautious of phishing lures mimicking legitimate games or government sites. Regularly updating devices and apps, and using multi-factor authentication on financial and messaging apps can reduce risk. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps"]
Adversary
AndroidKitKat
Pulse Id
6a8474eb4f130dfa41887e40
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip45.192.12.34
ip209.99.184.50
ip209.99.187.28
ip104.251.180.179
ip45.150.34.77

Hash

ValueDescriptionCopy
hash3530b1600e059468e585d48482bb2f37
hash41d922a220ac28a4af8cbed3ffff517b
hash471bcf065c6ed44282c5776ee78bc6d0
hashb7e9072e5bda17e0c68db01010658481
hashd472e984c6e8f3d4d7352125ebcc7c3c
hash54bccb0626f91a85d70803f4ecadd5cbd303f5e9
hash3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9
hash41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0
hashb7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f

Url

ValueDescriptionCopy
urlhttp://www.murlauncher.com/fenrir-launcher
urlhttps://sandbox-adventure.com/lifted-dreams/game
urlhttps://www.murlauncher.com/fenrir-launcher

Threat ID: 6a84b755c6e8be0332ab733c

Added to database: 08/18/2026, 19:49:41 UTC

Last enriched: 08/18/2026, 20:24:16 UTC

Last updated: 08/19/2026, 00:11:18 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses