Security News

New Android Malware 'MantaxOtax' Locks Phones While Stealing Personal Data

Infosecurity Magazine · 10 Sept 2026
Key Takeaway Australian small businesses should ensure staff only install apps from official app stores and avoid sideloading APK files from unofficial websites or file-sharing services.

Security researchers at Zimperium have identified a new strain of Android malware, dubbed MantaxOtax, that blends ransomware and spyware into a single threat. Linked to Indonesian threat actors, the malware appears to spread through sideloading, meaning it is installed from outside the official Google Play Store via a third-party file-sharing service rather than through normal app store checks.

Once installed, MantaxOtax requests a wide range of permissions, including device administrator rights, SMS and contact access, and Android's Accessibility service, which gives it deep control over how the device behaves. On older Android versions it can encrypt files stored on the device and demand payment through an in-app chat window, while on newer versions its ability to encrypt files is more limited due to Android's storage protections. Regardless of version, the malware also functions as a powerful spying tool, harvesting call logs, messages (including one-time passcodes), browsing history, location data, and even WhatsApp and Telegram content. It can silently take photos, record the screen and stream footage back to attackers.

The malware communicates with its command centre using a flexible system that resolves its control server address through GitHub, making it harder for defenders to shut down. Researchers also found that some of the attackers' own extortion conversations were exposed due to a server misconfiguration.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.