A new Android malware strain called Mantax Otax combines ransomware, spyware, remote-control, and harassment capabilities. Indonesian operators distribute it through malicious APKs hosted outside Google Play, using phishing and social engineering messages.
After installation, Mantax Otax requests Accessibility service access, then retrieves its command-and-control (C2) domain from GitHub. It sends victim details, including location, carrier, Android version, and device ID. Commands can arrive through Firebase or WebSockets.
The ransomware module targets devices running Android version 9 or older. It searches shared storage and encrypts selected file types with a victim-specific AES key from the C2 server, deletes the originals, and adds the “.enc” extension. It also replaces local images with ransom notices and opens a Firebase-hosted chat for payment negotiations.
The spyware can steal lock-screen PINs, read SMS and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location, and extract WhatsApp and Telegram data through simulated Accessibility interactions. It can capture screenshots, record MP4 videos, stream the screen through Catbox, and take photographs.
Version 2 added repeated dialog boxes, full-screen videos, “jumpscare” image overlays, and remotely controlled text-to-speech messages. Zimperium researchers say up-to-date Android devices with active Play Protect already detect and block Mantax Otax.
Comments
0No comments yet. Be the first to comment.