A Fake Bahraini Air-Raid App Turns Phones Into Listening Posts — and It Isn't Iran
Attackers cloned Bahrain's Civil Defence branding and the Play Store to push a four-stage Android implant to Gulf civilians during live missile alerts. The researchers found Cyrillic in the code and no state at all.
Analysis published by Dream Security on July 20 and picked up on July 22 describes fake "BH Alert" pages impersonating Bahrain's Civil Defence, the Ministry of Interior and the Information and eGovernment Authority, citing the UN disaster-risk office for legitimacy and running bilingually. The chain unpacks through four stages into a remote-access tool the developers called OctagonPanel, capable of capturing lockscreen PINs and patterns, intercepting SMS, taking screenshots, overlaying banking apps and driving the interface remotely. Its cleverest component is a fake VPN that advertises public DNS resolvers, routes all traffic into a tunnel and simply drops it — while exempting the attacker's own packages — coercing victims to finish setup before it self-terminates after fifteen minutes. Delivery pages claimed more than 100,000 downloads and a forged "Verified by Play Protect" badge. Attribution points to a Russian-speaking developer: Cyrillic artefacts, and a package name derived from the Russian for "kitty."
Assessment: The instructive part is who it is not. During a war in which Gulf civilians are receiving genuine air-raid warnings, an actor weaponised the state's own emergency branding — and the researchers explicitly say they see no evidence of nation-state involvement. Several outlets nonetheless framed it as Iranian, which is precisely the reflex to resist: wartime raises the value of impersonating a government to ordinary criminals too, and misattributing it upward both flatters the adversary and misdirects the defence. The practical Gulf lesson is narrower and more useful — emergency alerting is now a phishing surface, and any state that pushes warnings to citizens needs a single, publicised, verifiable channel. Caveat: this is static analysis by a boutique vendor, with no victim count and no operator identified.