Updated
Updated · eSecurity Planet · Sep 14
Zimperium Uncovers Mantax Otax Android Malware That Encrypts Android 9 Files and Steals OTPs
Updated
Updated · eSecurity Planet · Sep 14

Zimperium Uncovers Mantax Otax Android Malware That Encrypts Android 9 Files and Steals OTPs

1 articles · Updated · eSecurity Planet · Sep 14

Summary

  • Mantax Otax can pair ransomware with spyware on one infected Android device, encrypting files on Android 9 or earlier while also harvesting SMS one-time passwords, chats, screens, photos and location data.
  • Malicious APKs distributed outside Google Play appear to be the main entry point, with phishing and social engineering used to win device administrator, Accessibility and other high-risk permissions.
  • GitHub-hosted command-and-control addresses let the malware register each phone and receive instructions to raid contacts, call logs, browser history and media, while abusing MediaProjection and the camera for live surveillance.
  • A misconfigured Firebase server showed the extortion flow after encryption: victims were pushed into an on-screen chat for ransom talks, and newer samples added intrusive dialogs, touch blocking and fake lock screens to pressure payment.
  • Android 10's scoped storage sharply limits the malware's file-encryption reach, but newer devices still face credential theft, app abuse and screen-blocking risks; Zimperium linked the observed operation to Indonesian threat actors.

Insights

How does a seemingly harmless app use jumpscares and text-to-speech to terrorize Android users into paying hefty ransoms?
Could Android's built-in accessibility features be the exact tools hackers use to secretly drain your bank accounts today?