New Android malware encrypts files, steals data, and harasses victims
AI Generated Image

New Android malware encrypts files, steals data, and harasses victims

BleepingComputer technology

Key Points:

  • Mantax Otax is a new Android malware combining ransomware and spyware, capable of encrypting files, stealing sensitive data, and harassing victims through spam and intimidation tactics.
  • Distributed by Indonesian operators via malicious APKs outside Google Play, the malware uses phishing and social engineering to trick users into installing it and granting Accessibility service permissions for extensive device control.
  • The ransomware targets devices running Android 9 or older by encrypting files with AES keys, replacing images with ransom notes, and facilitating ransom negotiations through a Firebase-hosted chat, while newer Android versions limit its encryption capabilities.
  • Beyond ransomware, Mantax Otax steals lock-screen PINs, SMS, call logs, contacts, app data, and messages from WhatsApp and Telegram, and can capture screenshots, videos, and photos remotely, with version 2 introducing harassment features like pop-ups and text-to-speech messages to pressure victims.
  • Google’s Play Protect service detects and blocks Mantax Otax on updated devices, and users are advised to avoid installing APKs from untrusted sources, deny suspicious Accessibility permissions, and only download apps from reputable publishers.

Trending Business

Trending Technology

Trending Health