New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data
Security researchers at Zimperium have identified a new strain of Android malware, dubbed MantaxOtax, that blends ransomware and spyware into a single threat. Linked to Indonesian threat actors, the malware appears to spread through sideloading, meaning it is installed from outside the official Google Play Store via a third-party file-sharing service rather than through normal app store checks.
Once installed, MantaxOtax requests a wide range of permissions, including device administrator rights, SMS and contact access, and Android's Accessibility service, which gives it deep control over how the device behaves. On older Android versions it can encrypt files stored on the device and demand payment through an in-app chat window, while on newer versions its ability to encrypt files is more limited due to Android's storage protections. Regardless of version, the malware also functions as a powerful spying tool, harvesting call logs, messages (including one-time passcodes), browsing history, location data, and even WhatsApp and Telegram content. It can silently take photos, record the screen and stream footage back to attackers.
The malware communicates with its command centre using a flexible system that resolves its control server address through GitHub, making it harder for defenders to shut down. Researchers also found that some of the attackers' own extortion conversations were exposed due to a server misconfiguration.