← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

New Android Malware Mantax Otax Combines Ransomware and Spyware Capabilities

🔄 Updated 34m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Mantax Otax malware combines ransomware and spyware features.
  • It encrypts files on Android 9 and older devices, adding a '.enc' extension.
  • The malware steals sensitive data, including PINs, SMS, contacts, and browsing history.
  • It is distributed through malicious APKs outside Google Play, primarily by Indonesian operators.

New Android Threat Identified

Security researchers have identified a new Android malware strain named Mantax Otax. This malware integrates both ransomware and spyware functionalities, allowing it to encrypt user files, exfiltrate sensitive data, and engage in victim harassment through spamming.

Distribution and Initial Compromise

Indonesian operators are distributing Mantax Otax through malicious APK files hosted outside of Google Play, Android's official app store. Victims are targeted using phishing and social engineering messages to trick them into installing the malware. Upon installation, Mantax Otax requests Accessibility service permissions, granting it extensive control over the compromised device.

Ransomware Functionality

Mantax Otax's ransomware module specifically targets Android devices running version 9 or older. It searches shared storage for specific file types and encrypts them using a unique AES key obtained from its command-and-control (C2) server. The original files are then deleted, and encrypted copies receive a '.enc' extension. The malware replaces local images with ransom notices and opens a full-screen chat for ransom negotiations.

Spyware and Harassment Capabilities

Beyond ransomware, Mantax Otax includes comprehensive spyware features. It can steal lock-screen PINs, read SMS messages and one-time passwords, access call logs, contacts, browsing history, app lists, and Google account information. The malware also extracts WhatsApp profiles and messages, as well as Telegram chats, by simulating user interactions via Accessibility services. Additionally, it abuses the MediaProjection API to capture screenshots, record videos, and stream the victim's screen in near real-time.

Technical Details and Limitations

After installation, Mantax Otax retrieves its C2 domain from GitHub and sends device details like location, carrier, Android version, and device ID. The C2 can issue commands via Firebase or WebSockets. The ransomware module's effectiveness is limited to Android 9 and older due to 'Scoped Storage' security features introduced in Android 10, which restrict encryption capabilities to the external-files directory. Researchers were able to exploit a misconfiguration in the Firebase C2 server, exposing attacker-victim chats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Sep 10

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new Android malware, Mantax Otax, encrypts files, steals data, and harasses victims, combining ransomware and spyware functions. This malware targets older Android versions (9 and below) and is distributed via malicious APKs outside Google Play, posing a threat to users who install apps from unofficial sources.