Families in Bahrain have been warned against downloading a fake emergency alert app that poses as an official civil defence service but secretly installs malware capable of stealing passwords, banking credentials and other sensitive data.
According to a report by Dream Research Labs, the app, ‘BH Alert’ attempts to impersonate genuine Bahrain public institutions with the intention of luring people to trust it ... only for the stunned users to risk losing everything.
“Throughout July, GCC countries, including Bahrain and Kuwait, have been activating civil defence sirens and public safety guidance for residents in the wake of Iranian missiles,” said the report by Dream Research Labs, a global sovereign-AI and national cyberdefence company with offices in Abu Dhabi that works with national governments.
“During active air-defence events, official emergency-alert applications see sharp spikes in install demand,” it added.

The fake Google Play page with the malware app
“On July 17, Dream researchers analysed an Android application that impersonates a Bahraini Civil Defence called the ‘BH Alert’ siren app.
“It is distributed through a network of look-alike domains that clone the Google Play Store and official Bahraini government sites, complete with fake install animations.
“It deploys a four-stage surveillance platform capable of harvesting lockscreen credentials, SMS and one-time codes, contacts, and screenshots, running banking-app overlays, and taking full remote control of the device.
“It relies on social engineering and the abuse of legitimate Android permissions, delivered under a public-safety brand at a moment when users are primed to install it.”
According to the report, impersonating one of these apps in the middle of a live conflict is one of the most efficient ways to be trusted on a target’s device.
The malware does not have to break anything. It just needs to impersonate an official app to be granted access, and fear does the rest.
The app impersonates real Bahraini public institutions to establish trust with victims, including the Civil Defence, Interior Ministry and the Information and eGovernment Authority.
Hidden inside high-fidelity Google Play storefronts, the app shows that it has more than 100,000 downloads.

A fake website designed to get people to download the malware app
It also has fabricated reviews, and Data Safety claims that make the application appear established and legitimate. The words ‘air raid’, ‘shelter’ and other emergency alert language pressures the user to install the app.
Clicking on the install button triggers a timer-driven 20 MB download hosted outside Google Play, alongside a false Verified by Play Protect claim.
The page then displays simulated Installing and Installed states before delivering an Android Package Kit (APK) directly.
Scammers then use the malware to steal information such as banking credentials in order to forcefully withdraw money from the victim’s accounts.

The real siren alert
Before installing an app, the authorities urge people to check official websites or verified social media accounts for a direct link to the app to avoid any confusion.
Avoid installing anything from links on strange and unverified WhatsApp, SMS, email, or social media, and don’t assume it’s legitimate just because it looks convincing.
Attackers may create pages that closely resemble Google Play or other app stores. Check the web address carefully as the real Play Store uses the play.google.com domain.
Look out for extra words, misspellings, unusual domain endings, or URLs that redirect multiple times.
nader@gdnmedia.bh