Fake Bahrain Alert App Spreads Android Banking Spyware
Bahrain’s activation of civil-defense measures amid heightened regional missile threats has increased demand for emergency-alert tools, creating an opening for attackers to exploit public anxiety and trust in government services. On June 20, 2025, Bahrain’s Information & eGovernment Authority had urged residents to update the official MyGov app through authorized stores and enable its alerts feature, underscoring why convincing imitations can be especially dangerous during a conflict.
Dream Research Labs disclosed the BH Alert campaign on July 20, 2026, saying the malicious APK was distributed through counterfeit Google Play pages and spoofed Bahraini government sites. A four-stage infection chain deploys the OctagonPanel malware and Ward framework, enabling attackers to steal lock-screen credentials, SMS messages, one-time codes and banking logins. The remote-access trojan can also place phishing overlays over banking apps, capture screenshots, monitor devices through Android Accessibility Services and maintain operator control after a reboot.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.