New Android Malware Combines Ransomware and Spyware
A newly discovered malware named Mantax Otax targets Android devices and combines ransomware with spyware. Reports indicate that the malware encrypts data, steals sensitive information, and sends spam messages to victims. The security platform Bleepingcomputer has identified the malware, which appears to be distributed by developers in Indonesia. The distribution primarily occurs through APK files hosted outside the official Google Play Store. Users are specifically targeted through phishing and social engineering messages to install the malware.
After installation, the malware requests permissions for the accessibility service, granting it extensive control over the device. Once installed, Mantax Otax retrieves its command-and-control infrastructure (C2) via a domain from GitHub. The malware sends back information about the victim, including location, mobile carrier, Android version, and device ID. The C2 can then send commands to the infected device via Firebase or WebSockets. The malware causes significant damage by encrypting data on devices with older Android versions.
According to mobile security company Zimperium, a victim-specific AES key is used to encrypt certain file types. The original files are deleted and replaced with encrypted copies bearing the file extension “.enc.” In addition to ransom demands, the malware replaces local images with extortion messages and opens a full-screen chat to facilitate negotiations regarding the ransom payment. Besides encryption, Mantax Otax also steals screen lock PINs, reads SMS and one-time passwords, and has access to call logs, contacts, browsing history, and WhatsApp messages. A particularly concerning feature of the malware is its ability to secretly take photos using the device's camera.
Users running Android versions 9 or older are particularly vulnerable, while devices with Android 10 or newer are largely protected. This highlights the risks associated with using outdated Android versions. Currently, the attacks seem to primarily target users in Indonesia. To protect themselves, it is recommended to enable Google Play Protect, as this antivirus can detect Mantax Otax. Additionally, users should avoid installing APK files from outside the Google Play Store and ensure they regularly update to the latest Android version.
The latest generation of Android is currently Android 17. Security researchers advise installing additional antivirus software to ensure comprehensive protection. The threat posed by Mantax Otax underscores the importance of taking security precautions and regularly updating software. The malware was first identified in September 2026 and poses a serious threat to Android users, especially in regions with a high prevalence of older Android versions.
💬 Comments (0)
No comments yet. Be the first to comment!