CampaignSMS

Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers – cybersecuritynews.com

Octagon is an Android theft tool that turns an infected phone into a platform for account takeover.
It can steal login details, watch the screen, and capture verification codes that banks and exchanges use to protect accounts.
It is sold as a service, making financial fraud tools available to more criminals. Victims are lured into installing an Android app outside official stores, often one disguised by an unrelated theme, a fake store page, or a believable public-service message.
Analysts at iVerify identified Octagon in June 2026 and linked it to a Russian-speaking seller known as AndroidKitKat. 
iVerify said in a report shared with Cyber Security News (CSN) that the operation appeared on a Russian-language cybercrime forum on June 1.
Its advertised $1,400 monthly price and ready-made control panel make it notable beyond any one campaign.
Evidence suggests early use, but its focus on wallets, exchanges, banking apps, and messaging services creates a direct path to theft.
Octagon abuses Android accessibility features. When a victim enables the requested access, the malware can read screen content, inspect app interfaces, place fake forms over legitimate apps, and let a remote operator control the device.
The fake forms can request a wallet recovery phrase, password, or other account detail, then return the answer to the operator.
Like Crocodilus Android malware analysis, Octagon uses accessibility access and overlay pages against financial apps. The related Lifted Dreams build asks to read, receive, and send SMS messages.
It stores and forwards incoming texts, including one-time passcodes, allowing an attacker to answer an SMS-based login challenge after stealing a password or taking control of a victim’s session.
That turns a single compromised phone into a powerful fraud tool. Operators can collect screenshots, capture unlock patterns, PINs, and passwords, and simulate taps or text entry.
Supplied templates include Trust Wallet, Binance, and MEXC, with other wallet and exchange targets visible in the panel.
The Android implant connects to a Windows-based control panel. Buyers can check apps and balances, push a tailored overlay, and steer the screen in real time.
This on-device fraud model can work around warnings that might otherwise stop a suspicious web login.
Researchers recovered three related APK samples that share a client design, encrypted control connection, accessibility setup, and overlay assets.
One loaded a harmless-looking launcher page; another revealed a Lifted Dreams visual novel after seeking permissions.

A related Bahrain operation used fake government and Google Play pages and a four-stage APK chain.
Readers should be wary of unsolicited links and prompts to install files, a risk also seen in fake Play Store delivery, where deceptive pages delivered Android malware.
The malware may keep running even while Google Play Protect reports no harmful apps.
That finding does not invalidate platform protection, but it shows how social engineering and user-approved accessibility access can give a malicious app broad visibility and control after installation.
Install banking and wallet apps only from their official sources, and never grant accessibility access to unfamiliar software.
Treat unexpected requests for SMS, call, battery, or app-install permissions as a warning. If compromise is suspected, disconnect the phone, contact the provider through a trusted route, and reset credentials from a clean device.
Defenders can look for sideloaded apps that combine accessibility, app discovery, foreground execution, wake locks, and battery exclusions.
They should investigate encrypted TCP traffic on port 4444 and hunt for the shared identifiers in the table, rather than depending only on servers or cover pages that operators can replace.
For crypto users, recovery phrases are master keys, not ordinary verification information.
They should never be typed into a pop-up overlay, game-like installer, or unexpected support page. The SparkKitty wallet theft case similarly shows the danger of exposing wallet recovery material to untrusted apps.
Indicators of Compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
© Copyright 2026 – Cyber Security News

source

Leave a Reply

Your email address will not be published. Required fields are marked *