A new Android malware strain known as Mantax Otax is combining ransomware, spyware and remote-control tools to encrypt victims’ files, steal personal information and intimidate them into paying a ransom, security researchers have warned.
The malware is being distributed by operators in Indonesia through malicious Android application packages hosted outside Google Play. Victims are reportedly targeted with phishing messages and other social-engineering tactics designed to persuade them to install the software.
Once installed, Mantax Otax asks for access to Android’s Accessibility service. That permission can give an app broad control over a device, including the ability to interact with other applications and read information displayed on screen.
Researchers at mobile security firm Zimperium said the malware obtains the address of its command-and-control server from GitHub before sending details including the victim’s location, mobile carrier, Android version and device identifier. Commands can then be delivered through Firebase or WebSockets.
Android malware encrypts files on older devices
Mantax Otax’s ransomware function searches shared storage for selected file types and encrypts them using an AES key supplied by the attackers. The original files are deleted and the encrypted versions are given an “.enc” extension.
The ransomware element is limited mainly to devices running Android 9 or earlier. Android 10 introduced Scoped Storage, which restricts how applications access external files and significantly reduces the malware’s ability to encrypt data across a device.
After encrypting files, the malware can replace victims’ images with ransom notices and display a full-screen chat interface hosted through Firebase, allowing the attackers to negotiate payment. Zimperium said a misconfiguration in the Firebase infrastructure exposed conversations between the operators and victims.
The threat extends well beyond file encryption. Zimperium said Mantax Otax can capture lock-screen PINs, read text messages and one-time passwords, access call logs, contacts, browsing history, installed applications, Google account information and location data.
It can also use simulated taps and other interactions through Accessibility services to obtain WhatsApp profiles and messages, as well as Telegram conversations. The malware is capable of taking screenshots, recording video and streaming a device’s display almost in real time using Android’s MediaProjection technology.
Further surveillance functions include taking photographs with the infected device’s cameras and uploading them to the operators.
A second version has added features intended to frighten or pressure victims, including repeated pop-up messages, full-screen videos, sudden image overlays and remotely controlled text-to-speech announcements played through the device’s speakers. Researchers said these functions appear designed to reinforce demands for payment.
Zimperium said its status as a Google security partner through the App Defense Alliance means Mantax Otax is detected and blocked by updated Android devices running an active Play Protect service.
Users are advised to avoid installing APK files obtained outside Google Play, particularly when they arrive through unsolicited messages. They should also treat requests for Accessibility permissions with caution and only install applications from publishers they can verify.
