MEXC.com A.I CyberSecurity Scoring
MEXC.com
Company Information
Website:https://www.mexc.com
Employees number:19
Number of followers:0
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:mexc.com
MEXC.com Risk Score (AI oriented)
Between 750 and 799
MEXC.comTechnology, Information and Internet
Updated:
18/08/2026
18/08/2026
797/1000
Fair
Baa
MEXC.com Global Score (TPRM)
xxxx
MEXC.comTechnology, Information and Internet
Score locked

MEXC.comFair
Current Score
797Baa (FAIR)
01000
1 incidents
-25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
797
AUGUST 2026
797
JULY 2026
797
JUNE 2026
821
Cyber Attack
01 Jun 2026 • MEXC.com
MEXC: Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
New Android Malware-as-a-Service Platform 'Octagon' Targets Banking and Crypto Users
796
CRITICAL-25
MEX1787049361
New Android Malware-as-a-Service Platform "Octagon" Targets Banking and Crypto Users
A previously undocumented Android malware platform, Octagon, has emerged as a sophisticated malware-as-a-service (MaaS) offering from a Russian-speaking threat actor operating under the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, Octagon combines accessibility abuse, remote control, credential theft, SMS interception, and device reconnaissance to enable account takeovers and cryptocurrency theft.
### Key Capabilities & Attack Chain
Octagon operates as a turnkey subscription service, priced at $1,400 per month, targeting crypto wallets, exchanges, banking apps, messaging services, and Android lock screens. The malware disguises compromised devices as "Wards" in its control panel, granting operators visibility into installed apps, screen content, account balances, and accessibility-node data.
Once installed via sideloaded APKs, Octagon tricks victims into enabling Android Accessibility Services, allowing attackers to:
- Inspect and manipulate interface elements in targeted apps.
- Execute gestures, input text, and trigger system actions without traditional remote-access permissions.
- Deploy phishing overlays (e.g., fake Trust Wallet, Binance, or MetaMask login screens) to steal seed phrases, passwords, and PINs.
- Capture unlock patterns by targeting Android System UI and vendor lock screens, ensuring persistence even if victims attempt to secure their devices.
The malware also includes hidden VNC-style remote control, enabling operators to view and interact with the victim’s screen, capture screenshots, and send taps or swipes. Additionally, it intercepts SMS messages to bypass two-factor authentication (2FA), forwarding verification codes to attackers.
### Technical Details & Infrastructure
Octagon’s Windows-based command-and-control (C2) panel communicates with infected devices over TCP port 4444, using AES-GCM encryption for traffic. Researchers identified three linked APKs "Octagon," "Lifted Dreams," and "BahrDate" sharing core components, including:
- WardAccessibilityService (for accessibility abuse).
- OctagonBridge (for data exfiltration).
- Custom HTML WebView overlays impersonating Trust Wallet, Binance, MEXC, and TON Keeper.
Persistence mechanisms include boot execution, foreground services, isolated processes, and battery-optimization bypasses, ensuring the malware remains active despite Android’s power-saving features.
### Delivery & Campaigns
Octagon spreads via sideloaded APKs disguised as legitimate apps, such as:
- "Lifted Dreams" (a fake visual-novel game).
- A Bahrain Civil Defense-themed lure, using fake Play Store pages and government branding to trick victims.
A multi-stage APK chain was observed in one campaign, with the final payload matching Octagon’s package name (com.kisa.octagonpanel) and infrastructure.
### Impact & Detection Challenges
Octagon’s session-hijacking capabilities allow attackers to bypass risk engines by operating from the victim’s trusted device, IP, and unlocked accounts, making fraud harder to detect. Since the malware abuses manually granted permissions, Google Play Protect may not flag it as harmful, leaving users vulnerable even after scans.
Defenders are advised to monitor for:
- Sideloaded apps requesting accessibility access alongside SMS permissions.
- Encrypted outbound TCP traffic on port 4444 with Octagon’s shared client strings.
- Unusual battery-optimization exclusions or foreground service execution.
The platform’s modular design allows affiliates to rapidly change C2 infrastructure, complicating long-term tracking. Researchers have released indicators of compromise (IOCs), including APK hashes, C2 IPs, and package names, to aid detection.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
821
APRIL 2026
821
MARCH 2026
821
FEBRUARY 2026
821
JANUARY 2026
821
DECEMBER 2025
821
NOVEMBER 2025
821
OCTOBER 2025
821
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MEXC.com ??
What was MEXC.com's A.I Rankiteo Cyber Score in August 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in July 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in June 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in May 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in April 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in March 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in February 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in January 2026 ??
What was MEXC.com's A.I Rankiteo Cyber Score in December 2025 ??
What was MEXC.com's A.I Rankiteo Cyber Score in November 2025 ??
What was MEXC.com's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on MEXC.com's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MEXC.com ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MEXC.com's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?