Fake Bahrain Alert App Spreads Android Surveillance Malware

A fake emergency alert app targets users with sophisticated spying tools.

ThreatVectr Newsdesk· 2 min read
A dynamic, digital visualization of open source code intersecting with AI technology, symbolizing cybersecurity and vulnerability management
Share

Key points

  • Dream Research found the BH Alert app posed as a Bahraini government emergency alert on July 20.
  • The app can take full control of Android devices, collecting sensitive data and credentials.
  • It spreads through fake Google Play Store pages mimicking official Bahraini sites.

Dream, a cybersecurity firm focusing on national defense and critical infrastructure, reported on July 20 that a fake Android app is posing as a Bahraini emergency alert tool. This malicious app, named BH Alert, is not on the real Google Play Store but on lookalike sites that trick users into downloading spyware instead.

This app was discovered by Dream researchers, who noted that it camouflages itself as a legitimate civil-defense application. It claims to provide crucial updates during emergencies, but instead, it installs a program that can spy on users' devices. The app collects sensitive information like lockscreen passwords, text messages, and one-time codes. It can also take screenshots, run fake banking overlays, and even control the device remotely.

The criminals behind this app use fear to drive downloads. Recently, as tensions rose in the Gulf with Iranian missile strikes, people rushed to download emergency alert apps. The BH Alert app took advantage of this surge in demand by pretending to be a trusted government resource.

How did the hackers get in?

The fake app is spread through links shared on social media and messaging services, directing users to deceptive websites. These sites mimic the Google Play Store and use names like Bahrain Civil Defense and the Ministry of Interior to appear authentic. They have fake download counts and reviews to seem credible.

Once installed, the app asks for permissions that seem necessary for receiving emergency alerts. However, these permissions are actually used to install and activate the malware, which is designed to keep spying on the user even after the phone is restarted.

Dream noted that this type of attack combines the wide distribution of apps with the trust people place in government-related software. The app's developers exploit moments of fear, when people are less likely to question the authenticity of the app.

For organizations, mobile device management (MDM) tools can help control what apps are installed on company devices and prevent unauthorized installations. Network monitoring can also spot the malware's unusual network activity, which communicates with its controllers every five seconds.

This is not the first time Dream has uncovered such an attack. In March, they reported on a similar case involving a fake Israeli app. These incidents highlight the need for vigilance and proper security measures to protect against deceptive applications.

© 2026 Threat Vectr