Mantax Otax Android Malware Steals Data, Encrypts Files, and Disrupts Devices
Zimperium zLabs has analyzed a malicious Android APK called Mantax Otax, which combines ransomware, spyware, and device harassment capabilities in a single package. The malware is distributed via external file-sharing links and tricks users into granting Accessibility, device administrator, and other sensitive permissions after manual installation. Once active, it exfiltrates SMS messages, OTPs, PINs, location data, screenshots, and photos, while encrypting user files using victim-specific AES keys and demanding ransom through a built-in chat interface. File encryption is more extensive on Android 9 and earlier, though data theft remains a serious risk on Android 10 and later. Based on targeted file types and language indicators, researchers assess the campaign is primarily aimed at users in Indonesia.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in