security••4 min read

MantaxOtax: The Dangerous New Android Malware Merging Ransomware and Spyware

A sophisticated new Android malware strain known as MantaxOtax has emerged, combining file-encrypting ransomware with invasive spyware capabilities. Targeting users primarily in Indonesia, this threat grants attackers total control over compromised handsets.

MantaxOtax: The Dangerous New Android Malware Merging Ransomware and Spyware

A Double-Edged Threat for Android Users

A dangerous new Android malware strain dubbed MantaxOtax has been identified, marking a concerning evolution in mobile threats. By fusing the destructive nature of ransomware with the stealthy intrusion of spyware, this malware provides attackers with a multi-functional toolkit to both extort victims and harvest sensitive personal data.

The malware is currently targeting users in Indonesia, primarily spreading through third-party file repositories where victims are tricked into sideloading the application. Once installed, the consequences for the user are severe.

How MantaxOtax Takes Control

Upon execution, MantaxOtax requests extensive permissions, including device administrator rights and access to the Android Accessibility service. These permissions grant the attackers near-total control over the device, allowing them to bypass standard security hurdles.

  • Spyware functionality: Capture screenshots, record device activity, intercept one-time passwords (OTPs), and exfiltrate chat logs from platforms like WhatsApp and Telegram.
  • Ransomware capabilities: Encrypt files on the device using unique keys retrieved from a remote command-and-control (C2) server.
  • Remote operations: The malware resolves its C2 domain through a GitHub repository, allowing attackers to update their infrastructure without needing to modify the malware's source code.
  • User Interface Hijacking: It can lock the screen and display social engineering prompts, instructing victims to contact an external "administrator" to resolve issues.

The Technical Sophistication of MantaxOtax

What distinguishes MantaxOtax from traditional mobile threats is its high degree of versatility. Researchers at Zimperium noted that the malware utilizes the native Android MediaProjection API to perform continuous monitoring, including full-motion screen recording. Captured data is then exfiltrated to third-party hosting services.

The malware exhibits advanced user interface (UI) hijacking capabilities, persistently locking the device screen and dynamically restricting access to installed applications on the compromised asset.

— Zimperium zLabs Researchers

Protecting Your Device

The primary vector for this infection is the manual installation of applications from unverified, third-party sources. To mitigate the risk of falling victim to MantaxOtax or similar threats, users should stick exclusively to official app stores and be wary of granting excessive permissions—particularly Accessibility service access—to unknown applications.

Key Takeaways

  • MantaxOtax is a hybrid Android malware combining ransomware and spyware.
  • The malware is currently concentrated on users in Indonesia.
  • Attackers leverage Android Accessibility services to gain full control of the device.
  • The threat can steal 2FA codes, chat logs, and perform live screen recording.
  • Distribution primarily occurs through third-party sideloading sites.

FAQ

What is MantaxOtax?

MantaxOtax is a new Android malware strain that combines file-encrypting ransomware with spyware to steal data and extort victims.

How does MantaxOtax infect devices?

It primarily spreads through third-party file repositories where users are tricked into manually downloading and installing the malicious app.

What kind of data can MantaxOtax steal?

It can capture screenshots, record screen activity, intercept OTPs, and steal chat logs from encrypted messaging apps like WhatsApp and Telegram.

Does the malware encrypt device files?

Yes, it initiates a cryptographic phase using keys retrieved from a remote server to encrypt files on the infected device.

How can I protect myself from MantaxOtax?

Only download apps from official app stores like Google Play, avoid sideloading apps from third-party sites, and be cautious when granting permissions to new apps.

Related Videos

Mantax Otax Android Malware: Steals OTPs, Spies on WhatsApp & Encrypts Your File

CyberRakshakLabs

Sources