New Android malware encrypts files, steals data, and harasses victims

A New Breed of Android Malware Spells Trouble for Users with Older Devices

A highly sophisticated strain of Android malware has been identified, capable of encrypting files, stealing sensitive data, and even harassing its victims. Dubbed Mantax Otax, this malicious software is being distributed through phishing and social engineering messages by Indonesian operators, targeting users with vulnerable devices running older versions of the operating system.

Mantax Otax’s encryption module targets Android versions 9 and below, exploiting a security loophole that allows it to access sensitive files on shared storage. Once encrypted, these files are deleted, leaving victims with no choice but to pay the ransom. The malware also replaces local images with ransom notes, adding an intimidating element to its attacks.

But Mantax Otax’s capabilities don’t stop there. This dual-purpose malware combines ransomware and spyware features, allowing it to steal lock-screen PINs, read SMS messages and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location data. It can even extract WhatsApp profiles and messages, as well as Telegram chats, by simulating interactions via Accessibility services.

One of the most disturbing features of Mantax Otax is its ability to capture screenshots, record MP4 videos, and stream the victim’s screen in near real-time. This is achieved through the MediaProjection API, which allows the malware to abuse Android’s built-in functionality. The malware can also capture photographs using the infected device’s cameras and upload them to the operator.

The inclusion of harassment features in version 2 of the malware adds an additional layer of intimidation to the attacks. These features include repeated dialog boxes, full-screen videos, rapid “jumpscare” image overlays, and remotely controlled text-to-speech messages played through the device speakers. This pressure mechanism is designed to coerce victims into paying the ransom.

Fortunately, users with up-to-date Android devices and an active Play Protect service are already protected against this malware thanks to Zimperium’s partnership with Google via the App Defense Alliance (ADA). However, for those running older versions of Android, it’s essential to exercise caution when installing APKs from outside the official app store.

To stay safe, users should be wary of downloading apps from unknown sources and avoid granting Accessibility permissions to suspicious applications. It’s also crucial to trust reputable publishers and keep software up-to-date to prevent such malicious attacks. By being vigilant and taking proactive measures, Android users can minimize their exposure to threats like Mantax Otax.


Source: Bleeping Computer — 2026-09-10