Security researchers have identified a new Android malware strain named Mantax Otax. This malware integrates both ransomware and spyware functionalities, allowing it to encrypt user files, exfiltrate sensitive data, and engage in victim harassment through spamming.
Indonesian operators are distributing Mantax Otax through malicious APK files hosted outside of Google Play, Android's official app store. Victims are targeted using phishing and social engineering messages to trick them into installing the malware. Upon installation, Mantax Otax requests Accessibility service permissions, granting it extensive control over the compromised device.
Mantax Otax's ransomware module specifically targets Android devices running version 9 or older. It searches shared storage for specific file types and encrypts them using a unique AES key obtained from its command-and-control (C2) server. The original files are then deleted, and encrypted copies receive a '.enc' extension. The malware replaces local images with ransom notices and opens a full-screen chat for ransom negotiations.
Beyond ransomware, Mantax Otax includes comprehensive spyware features. It can steal lock-screen PINs, read SMS messages and one-time passwords, access call logs, contacts, browsing history, app lists, and Google account information. The malware also extracts WhatsApp profiles and messages, as well as Telegram chats, by simulating user interactions via Accessibility services. Additionally, it abuses the MediaProjection API to capture screenshots, record videos, and stream the victim's screen in near real-time.
After installation, Mantax Otax retrieves its C2 domain from GitHub and sends device details like location, carrier, Android version, and device ID. The C2 can issue commands via Firebase or WebSockets. The ransomware module's effectiveness is limited to Android 9 and older due to 'Scoped Storage' security features introduced in Android 10, which restrict encryption capabilities to the external-files directory. Researchers were able to exploit a misconfiguration in the Firebase C2 server, exposing attacker-victim chats.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new Android malware, Mantax Otax, encrypts files, steals data, and harasses victims, combining ransomware and spyware functions. This malware targets older Android versions (9 and below) and is distributed via malicious APKs outside Google Play, posing a threat to users who install apps from unofficial sources.