deltanfts

Decoding the economy of virtual worlds

Octagon Android Trojan: How This $1,400 Malware Targets Crypto Wallets

iVerify's threat intelligence team documented Octagon on June 1, 2026: a sideloaded Android trojan sold as malware-as-a-service by a Russian-speaking developer operating under the handle…

Octagon Android Trojan: How This $1,400 Malware Targets Crypto Wallets

Octagon Prices Mobile Crypto Theft at $1,400/Month

iVerify's threat intelligence team documented Octagon on June 1, 2026: a sideloaded Android trojan sold as malware-as-a-service by a Russian-speaking developer operating under the handle AndroidKitKat on a Russian-language cybercrime forum (member ID 221700). Listed at $1,400 per month, the toolkit pairs hidden VNC, SMS and OTP interception, unlock-pattern capture, and live on-screen balance reading. The delivery app can carry an unrelated theme. For GameFi participants holding token treasuries or in-game asset wallets on Android, this is a direct exposure vector.

Mechanics

The Windows command-and-control panel pairs each compromised device — labeled a "Ward" — with an installed-app roster and a live balance field. The Android package, com.kisa.octagonpanel, registers WardAccessibilityService through ward_accessibility_config and adds a foreground service that persists after installation.

  • Preloaded overlay templates: Trust Wallet, Binance, MEXC, with custom-template support
  • Version 1.1 changelog advertises 457 built-in target definitions
  • Editable HTML WebView overlays request seed phrases, passwords, and OTPs
  • Hidden VNC gives the operator full screen and input control
  • Google Play Protect reads "No harmful apps found" while accessibility reads the same screen
  • Telegram, WhatsApp, and Viber appear in the target set alongside crypto wallets

Sales material runs in English; backend logs and Telegram history run in Russian. iVerify recovered three APKs with high confidence, publishing sample hashes in the report. Version 1.2 dropped June 29, 2026. The operator advertises a Restricted Settings bypass; Dream Group separately documented fake store and government lures for a related payload.

What to Adjust

The exploit path requires the victim to enable Android accessibility manually. That's the entry point. Treat any app requesting accessibility for unrelated functionality — a flashlight, a launcher, a QR scanner — as hostile.

  • Move treasuries sized above one device-loss event into cold storage on hardware wallets that never touch the phone
  • Treat accessibility grants as root-level access; deny by default
  • Verify sideloaded APKs against vendor-published hashes before installation
  • Keep hot-wallet balances at what you'd accept losing in a single phone compromise
  • Buy cold-storage devices sealed in tamper-evident packaging; reject second-hand units with seller-supplied seeds

Watch for newer GameFi-native wallets and in-game asset managers added to the template list — that's where the blast radius widens for players running inventory on mobile. Separately, Ireland's new AML strategy, reported mid-August 2026, brings enhanced checks on private crypto wallets, layering a compliance front on top of the device-level threat.

Cross-border travel now carries parallel friction. Declaration and documentation rules at ports extend well beyond traditional goods — cigarette limits from the UK to Ireland post-Brexit illustrate how customs enforcement has widened its scope since Brexit.