A Double-Edged Threat for Android Users
A dangerous new Android malware strain dubbed MantaxOtax has been identified, marking a concerning evolution in mobile threats. By fusing the destructive nature of ransomware with the stealthy intrusion of spyware, this malware provides attackers with a multi-functional toolkit to both extort victims and harvest sensitive personal data.
The malware is currently targeting users in Indonesia, primarily spreading through third-party file repositories where victims are tricked into sideloading the application. Once installed, the consequences for the user are severe.
How MantaxOtax Takes Control
Upon execution, MantaxOtax requests extensive permissions, including device administrator rights and access to the Android Accessibility service. These permissions grant the attackers near-total control over the device, allowing them to bypass standard security hurdles.
- Spyware functionality: Capture screenshots, record device activity, intercept one-time passwords (OTPs), and exfiltrate chat logs from platforms like WhatsApp and Telegram.
- Ransomware capabilities: Encrypt files on the device using unique keys retrieved from a remote command-and-control (C2) server.
- Remote operations: The malware resolves its C2 domain through a GitHub repository, allowing attackers to update their infrastructure without needing to modify the malware's source code.
- User Interface Hijacking: It can lock the screen and display social engineering prompts, instructing victims to contact an external "administrator" to resolve issues.
The Technical Sophistication of MantaxOtax
What distinguishes MantaxOtax from traditional mobile threats is its high degree of versatility. Researchers at Zimperium noted that the malware utilizes the native Android MediaProjection API to perform continuous monitoring, including full-motion screen recording. Captured data is then exfiltrated to third-party hosting services.
The malware exhibits advanced user interface (UI) hijacking capabilities, persistently locking the device screen and dynamically restricting access to installed applications on the compromised asset.
— Zimperium zLabs Researchers
Protecting Your Device
The primary vector for this infection is the manual installation of applications from unverified, third-party sources. To mitigate the risk of falling victim to MantaxOtax or similar threats, users should stick exclusively to official app stores and be wary of granting excessive permissions—particularly Accessibility service access—to unknown applications.
