Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
Octagon is a newly identified Android malware-as-a-service bot discovered in June 2026, targeting cryptocurrency wallets, exchanges, and banking applications. It uses accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading to steal credentials and control infected devices remotely. Distributed via sideloaded APKs bypassing restricted settings, Octagon connects devices to a Windows command-and-control panel for real-time monitoring and manipulation. The malware maintains persistence through multiple mechanisms and evades detection by appearing benign to security scans. It has been observed using lures such as the Lifted Dreams game and Bahrain government-themed bait. Octagon specifically targets apps like Trust Wallet, Binance, MEXC, MetaMask, Telegram, and WhatsApp to facilitate cryptocurrency theft and account takeover.
AI Analysis
Technical Summary
Octagon is an Android fraud bot sold as malware-as-a-service by the Russian-speaking actor AndroidKitKat for $1,400 monthly. It employs multiple advanced techniques including accessibility overlays to capture user input, hidden VNC for remote device control, SMS interception, unlock-pattern capture, and balance reading to target cryptocurrency wallets, exchanges, and banking apps. The malware is distributed through sideloaded APKs that bypass Android's Restricted Settings protections. Once installed, it connects infected devices to a Windows-based command-and-control panel where operators can monitor applications, read device screens, and control devices remotely. Persistence is maintained through various mechanisms, and the malware is designed to appear benign to security scans. Three APK samples have been recovered, including those using the Lifted Dreams game and Bahrain government-themed lures. Credential theft is facilitated via HTML WebView overlays targeting popular crypto wallets and messaging apps, enabling theft of cryptocurrency and account takeover.
Potential Impact
Octagon enables attackers to remotely control infected Android devices, intercept SMS messages, capture unlock patterns, and steal credentials from targeted cryptocurrency wallets, exchanges, and banking applications. This can lead to unauthorized access to financial accounts, theft of cryptocurrency assets, and compromise of messaging apps. The malware's persistence and stealth capabilities increase the risk of prolonged undetected compromise on infected devices.
Mitigation Recommendations
No official patch or remediation is currently available as this is malware distributed via sideloaded APKs. Users should avoid installing applications from untrusted sources and sideloaded APKs. Security teams should monitor for indicators of compromise such as the provided IP addresses, hashes, and URLs associated with Octagon. Employ mobile threat defense solutions capable of detecting accessibility abuse and overlay attacks. Users should be cautious of phishing lures mimicking legitimate games or government sites. Regularly updating devices and apps, and using multi-factor authentication on financial and messaging apps can reduce risk. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Indicators of Compromise
- ip: 45.192.12.34
- ip: 209.99.184.50
- ip: 209.99.187.28
- hash: 3530b1600e059468e585d48482bb2f37
- hash: 41d922a220ac28a4af8cbed3ffff517b
- hash: 471bcf065c6ed44282c5776ee78bc6d0
- hash: b7e9072e5bda17e0c68db01010658481
- hash: d472e984c6e8f3d4d7352125ebcc7c3c
- hash: 54bccb0626f91a85d70803f4ecadd5cbd303f5e9
- hash: 3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9
- hash: 41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0
- hash: b7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f
- ip: 104.251.180.179
- ip: 45.150.34.77
- url: http://www.murlauncher.com/fenrir-launcher
- url: https://sandbox-adventure.com/lifted-dreams/game
- url: https://www.murlauncher.com/fenrir-launcher
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
Description
Octagon is a newly identified Android malware-as-a-service bot discovered in June 2026, targeting cryptocurrency wallets, exchanges, and banking applications. It uses accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading to steal credentials and control infected devices remotely. Distributed via sideloaded APKs bypassing restricted settings, Octagon connects devices to a Windows command-and-control panel for real-time monitoring and manipulation. The malware maintains persistence through multiple mechanisms and evades detection by appearing benign to security scans. It has been observed using lures such as the Lifted Dreams game and Bahrain government-themed bait. Octagon specifically targets apps like Trust Wallet, Binance, MEXC, MetaMask, Telegram, and WhatsApp to facilitate cryptocurrency theft and account takeover.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Octagon is an Android fraud bot sold as malware-as-a-service by the Russian-speaking actor AndroidKitKat for $1,400 monthly. It employs multiple advanced techniques including accessibility overlays to capture user input, hidden VNC for remote device control, SMS interception, unlock-pattern capture, and balance reading to target cryptocurrency wallets, exchanges, and banking apps. The malware is distributed through sideloaded APKs that bypass Android's Restricted Settings protections. Once installed, it connects infected devices to a Windows-based command-and-control panel where operators can monitor applications, read device screens, and control devices remotely. Persistence is maintained through various mechanisms, and the malware is designed to appear benign to security scans. Three APK samples have been recovered, including those using the Lifted Dreams game and Bahrain government-themed lures. Credential theft is facilitated via HTML WebView overlays targeting popular crypto wallets and messaging apps, enabling theft of cryptocurrency and account takeover.
Potential Impact
Octagon enables attackers to remotely control infected Android devices, intercept SMS messages, capture unlock patterns, and steal credentials from targeted cryptocurrency wallets, exchanges, and banking applications. This can lead to unauthorized access to financial accounts, theft of cryptocurrency assets, and compromise of messaging apps. The malware's persistence and stealth capabilities increase the risk of prolonged undetected compromise on infected devices.
Defensive Guidance
No official patch or remediation is currently available as this is malware distributed via sideloaded APKs. Users should avoid installing applications from untrusted sources and sideloaded APKs. Security teams should monitor for indicators of compromise such as the provided IP addresses, hashes, and URLs associated with Octagon. Employ mobile threat defense solutions capable of detecting accessibility abuse and overlay attacks. Users should be cautious of phishing lures mimicking legitimate games or government sites. Regularly updating devices and apps, and using multi-factor authentication on financial and messaging apps can reduce risk. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://iverify.io/blog/octagon-android-bot-crypto-wallets-banking-apps"]
- Adversary
- AndroidKitKat
- Pulse Id
- 6a8474eb4f130dfa41887e40
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip45.192.12.34 | — | |
ip209.99.184.50 | — | |
ip209.99.187.28 | — | |
ip104.251.180.179 | — | |
ip45.150.34.77 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash3530b1600e059468e585d48482bb2f37 | — | |
hash41d922a220ac28a4af8cbed3ffff517b | — | |
hash471bcf065c6ed44282c5776ee78bc6d0 | — | |
hashb7e9072e5bda17e0c68db01010658481 | — | |
hashd472e984c6e8f3d4d7352125ebcc7c3c | — | |
hash54bccb0626f91a85d70803f4ecadd5cbd303f5e9 | — | |
hash3530b1600e059468e585d48482bb2f375edfe5cb5c23862b01d8405ab56376b9 | — | |
hash41d922a220ac28a4af8cbed3ffff517bfc5087f11c52801a1be0353e22a71fe0 | — | |
hashb7e9072e5bda17e0c68db010106584815442b8a9e0ce05db8e3724d8c8967f4f | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://www.murlauncher.com/fenrir-launcher | — | |
urlhttps://sandbox-adventure.com/lifted-dreams/game | — | |
urlhttps://www.murlauncher.com/fenrir-launcher | — |
Threat ID: 6a84b755c6e8be0332ab733c
Added to database: 08/18/2026, 19:49:41 UTC
Last enriched: 08/18/2026, 20:24:16 UTC
Last updated: 08/19/2026, 00:11:18 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.