New Android Malware

Overview

A new Android malware strain called Mantax Otax has emerged, combining ransomware and spyware capabilities. Distributed by Indonesian operators through malicious APKs outside Google Play, the malware encrypts files, steals sensitive data, and even harasses victims with intimidation tactics.

Infection Chain

  • Phishing distribution: Delivered via malicious APKs hosted outside Google Play.
  • Accessibility abuse: Requests Accessibility service permissions to gain extensive device control.
  • C2 infrastructure: Retrieves domains from GitHub, communicates via Firebase or WebSockets, and sends victim details (location, carrier, Android version, device ID).

Ransomware Capabilities

  • File encryption: Encrypts shared storage files on Android 9 and older using victim‑specific AES keys.
  • Scoped Storage limitation: Android 10+ restricts encryption to external‑files directory.
  • Ransom notes: Replaces local images with ransom notices and opens Firebase‑hosted chat for negotiations.

Spyware & Harassment Features

  • PIN theft: Steals lock‑screen PINs to maintain persistent access.
  • Data exfiltration: Reads SMS, OTPs, call logs, contacts, browsing history, app lists, Google account info, and location.
  • Messaging theft: Extracts WhatsApp profiles/messages and Telegram chats via simulated interactions.
  • Screen capture: Uses MediaProjection API to record videos, stream screens, and capture screenshots.
  • Camera abuse: Takes photos and uploads them to operators.
  • Harassment tactics: Includes repeated dialog boxes, jumpscare overlays, full‑screen videos, and text‑to‑speech intimidation.

Defensive Guidance

Users should:

  • Avoid APKs outside Google Play.
  • Deny Accessibility permissions to untrusted apps.
  • Enable Play Protect for real‑time malware detection.
  • Update Android devices to benefit from Scoped Storage protections.
  • Monitor for harassment signs such as jumpscare overlays or repeated dialogs.

Expert in the Cloud Insight

Mantax Otax demonstrates how modern Android malware blends ransomware, spyware, and psychological harassment into a single package. By exploiting weak configurations and older Android versions, attackers weaponize everyday features like Accessibility and MediaProjection. The lesson is clear: security hygiene—patching, trusted app sources, and strict permission control—is the frontline defense against evolving mobile threats.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.