language
Automatically detected

We have pre-selected English and US Dollar ($) for you.

Log In
softwarebay.de
softwarebay.de
New Android Malware Threatens Users Worldwide
News Cybersecurity New Android Malware Threatens Users Worldwide
Cybersecurity

New Android Malware Threatens Users Worldwide

New Android Malware Threatens Users Worldwide

A newly discovered malware named Mantax Otax threatens Android users by encrypting their devices and stealing sensitive data. According to a report from Bleepingcomputer, it is a combination of ransomware and spyware that is primarily spreading in Indonesia. The malware is distributed via APK files hosted outside the Google Play Store and employs targeted phishing and social engineering techniques to persuade users to install it. After installation, Mantax Otax requests permission to use the accessibility service, granting the malware extensive control over the infected device. The malware communicates with its command-and-control infrastructure (C2) via a domain on GitHub and sends information about the victim, including location, mobile carrier, Android version, and device ID, back to the attackers.

The malware causes significant damage by encrypting data on devices with older Android versions. According to mobile security company Zimperium, this particularly affects devices running Android 9 or older. Mantax Otax uses a victim-specific AES key to encrypt certain file types and then deletes the original files while appending the encrypted copies with the file extension “.enc.” In addition to ransom demands, the malware replaces local images with extortion messages and opens a full-screen chat hosted by Firebase to facilitate negotiations over the ransom payment.

Besides encryption, Mantax Otax also steals screen lock PINs, reads SMS and one-time passwords, and has access to call logs, contacts, browsing history, app lists, WhatsApp messages, as well as Google account information and location data. A particularly concerning feature of the malware is its ability to secretly take photos using the camera of the infected device. This functionality significantly increases the risk to user privacy. The malware currently appears to be primarily targeting users in Indonesia, indicating a targeted campaign.

Users can protect themselves from Mantax Otax by enabling Google Play Protect, which is capable of detecting the malware. It is strongly recommended not to install APK files from outside the Google Play Store. Additionally, users should ensure they regularly perform Android updates and upgrade to the latest Android version whenever possible. Currently, Android 17 is the latest version of the operating system. Users who have upgraded to Android 10 or higher are largely protected from Mantax Otax attacks.

This highlights the risks associated with using outdated Android versions and the necessity of regularly updating devices. The spread of Mantax Otax underscores the importance of being aware of the dangers posed by malware. The combination of ransomware and spyware presents a serious threat to data security. Security researchers warn that attackers may continue to develop new methods to spread their malware and deceive users.

The vulnerability exploited by Mantax Otax could potentially affect millions of users, especially in regions with a high number of devices that are not regularly updated. Users should stay informed about the latest threats and take appropriate security measures to protect their data. The malware was first identified in September 2026 and has since caused a growing number of victims in Indonesia. Security analysts recommend remaining vigilant and monitoring for any suspicious activities on their devices.

Tags: Malware Android Security Ransomware Spyware Mantax Otax

💬 Comments (0)

Write a comment

info Will be published after moderation
chat_bubble_outline

No comments yet. Be the first to comment!

Live support available
Tiara S.
Tiara S.
check_circle Brasov
Hello! I am Tiara. Do you have questions about our products or need help?
chat_bubble