Fake Bahrain alert app installs Android spyware via phony Google Play sites
This digest was compiled by AI from multiple sources — links to the originals are below.

A malicious Android application posing as a Bahrain civil defense alert tool delivered four-stage spyware via fake Google Play pages. The campaign exploited civilian fear during Iranian missile strikes to trick users into sideloading the malware.
The Malware Campaign
Researchers at Dark Reading identified a four-stage Android spyware campaign targeting Bahraini civilians. The malware was distributed through fake Google Play store pages mimicking legitimate alert apps. The attackers exploited the heightened fear during Iranian missile strikes in April 2024 to increase infection rates.
Technical Details
The spyware uses a multi-stage delivery mechanism: first, a dropper app requests accessibility permissions; then it downloads a second-stage payload that evades Google Play Protect. The final payload exfiltrates SMS messages, call logs, and device location. The campaign primarily targeted Bahrain, with secondary infections in Saudi Arabia and the UAE.
Exploitation of Crisis
The attackers timed the campaign to coincide with Iranian missile strikes on Israel in April 2024, which triggered civilian fear in Gulf states. Fake social media posts urged users to install the 'Bahrain Alert' app for missile warnings. The app was never available on official Google Play, relying entirely on sideloading via phishing links.
What's Next
Google has not commented on the takedown of the fake sites. It remains unclear whether the spyware is linked to a known state actor or criminal group.
1 source
Fake Bahrain alert app installs Android spyware via phony Google Play sites



