A New Breed of Android Malware Emerges, Encrypting Files and Harassing Victims
In a disturbing development, researchers have uncovered a new strain of Android malware that combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and harass victims with repeated dialog boxes and full-screen videos. Dubbed Mantax Otax, this highly sophisticated threat is being distributed by Indonesian operators through phishing and social engineering messages, targeting users who download malicious APKs from outside the official Google Play app store.
Once installed, Mantax Otax requests permission to use the Accessibility service, which grants it extensive control over the compromised device. The malware then retrieves its command-and-control (C2) infrastructure from GitHub and sends back victim details such as location, carrier, Android version, and device ID to its operators. These details can be used to tailor the attack and extort higher ransoms.
One of the most concerning aspects of Mantax Otax is its ability to encrypt files on devices running older versions of Android (version 9 or earlier). The malware searches shared storage for targeted file types, encrypts them using a victim-specific AES key obtained from the C2 server, and deletes the original files. To add insult to injury, Mantax Otax replaces local images with ransom notices and opens a full-screen chat to facilitate payment negotiations. Researchers were able to exploit a misconfiguration in the Firebase C2 server, which exposed the attackers’ chats with victims.
But that’s not all – Mantax Otax also includes spyware, remote control, and harassment features. It can steal lock-screen PINs to maintain persistent access, read SMS and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location. The malware can even extract WhatsApp profiles and messages, as well as Telegram chats, using simulated interactions via Accessibility services.
Furthermore, Mantax Otax abuses Android’s MediaProjection API to capture screenshots, record MP4 videos, and stream the victim’s screen in near real time via the Catbox file hosting service. It can also capture photographs using the infected device’s cameras and upload them to the operator. The malware’s harassment functions include repeated dialog boxes, full-screen videos, rapid “jumpscare” image overlays, and remotely controlled text-to-speech messages played through the device speakers.
The good news is that Zimperium, a Google security partner via the App Defense Alliance (ADA), has already detected and blocked Mantax Otax on up-to-date Android devices with an active Play Protect service. To stay safe, users should exercise caution when downloading APKs from outside Google Play, refuse to grant questionable apps Accessibility permissions, and only trust reputable publishers.
In today’s increasingly complex cybersecurity landscape, it’s essential for Android users to remain vigilant and take proactive steps to protect themselves against emerging threats like Mantax Otax.
Source: Bleeping Computer — 2026-09-10