Cybersecurity

Mantax Otax: Android Malware Combines Ransomware, Spying, and Intimidation

Zimperium identified Android malware called Mantax Otax that encrypts files on older versions, steals sensitive data, and gives attackers extensive monitoring and control capabilities. It spreads through APK files outside Google Play, while updated Play Protect protection helps detect and block it.

2026-09-10
4 min read
10 views
فريق تحرير certi.news
Mantax Otax: Android Malware Combines Ransomware, Spying, and Intimidation

Mobile security company Zimperium identified new Android malware called Mantax Otax that combines ransomware, spyware, and remote-control functions, along with tools designed to harass victims and push them to respond to ransom demands. According to the available information, Indonesian operators distribute the malware through malicious APK files hosted outside Google Play, using phishing messages and social engineering to lure users into installing it.

After installation, Mantax Otax requests access to the Accessibility service, a permission that gives an application extensive ability to interact with the device interface and perform actions on the user’s behalf. The malware also obtains the command-and-control server address from GitHub, then sends operators information including the location, telecommunications carrier, Android version, and device identifier. The server can send commands using Firebase or WebSockets.

Encryption Targets Older Versions

The ransomware component operates on Android devices running version 9 or earlier. The malware searches shared storage for specific file types, then encrypts them using an AES key specific to the victim that it obtains from the command-and-control server. It then deletes the original files and adds the .enc extension to the encrypted copies.

It also replaces local images with ransom notifications and opens a full-screen chat interface hosted through Firebase to facilitate negotiations with the victim. Zimperium researchers were able to exploit a misconfiguration in the Firebase server, which exposed conversations between the attackers and victims.

The restriction of the encryption function to Android 9 and earlier is due to the fact that Scoped Storage, a feature introduced in Android 10 and later versions, significantly limits the malware’s ability to encrypt files outside application directories.

Extensive Spying and Device Control

Mantax Otax is not limited to encrypting files. It can steal the lock-screen PIN to help maintain access, read text messages and one-time passwords, and access call logs, contacts, browsing history, the application list, Google account information, and location data.

The findings also indicate that it can extract WhatsApp profiles and chats and Telegram conversations by simulating user interactions through the Accessibility service. It also exploits the MediaProjection interface to capture screenshots, record videos in MP4 format, and stream the device screen almost in real time through the Catbox file-hosting service, in addition to capturing images with the device’s cameras and uploading them to the operator.

Intimidation as Part of the Attack

The malware’s second version added psychological-pressure functions, including displaying repeated dialog boxes, playing full-screen videos, showing startling images rapidly, and playing text-to-speech messages controlled by the attacker through the speakers. These functions transform the attack from an extortion attempt based on file encryption into a direct intimidation tactic intended to increase pressure on the victim.

What Matters to Android Users?

The significance of this case lies in the combination of several sensitive capabilities within a single piece of malware: file encryption, theft of credentials and communications, screen and camera monitoring, and device control. However, the stated encryption scope is practically limited to devices running Android 9 or earlier, and Zimperium says that updated devices with Play Protect enabled detect and block Mantax Otax.

The direct measures established by the source are to avoid installing APK files from outside Google Play, not to grant untrusted applications Accessibility permission, and to rely on known publishers. This does not eliminate the need to review the application’s source and requested permissions, because the main entry point in this campaign is persuading the user to install the malicious package and grant it broad access to the device.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news