New Android Malware Mantax Otax Combines Ransomware and Spyware to Encrypt Data and Steal Information

Zimperium researchers identify Indonesian-operated malware that targets older Android devices and abuses Accessibility services

edit
By LineZotpaper
Published
Read Time2 min
A new Android malware strain called Mantax Otax, discovered by mobile security firm Zimperium, encrypts files on older devices while simultaneously stealing sensitive data and harassing victims through spam and social engineering. The malware is distributed via malicious APKs hosted outside Google Play, primarily by Indonesian operators using phishing and social engineering messages.

Mantax Otax is a hybrid malware that combines ransomware and spyware capabilities, according to a report from mobile security company Zimperium shared by BleepingComputer. The malware is distributed through malicious APKs outside Google Play, with Indonesian operators targeting victims via phishing and social engineering messages.

After installation, Mantax Otax requests permission to use Android's Accessibility service, granting it extensive control over the compromised device. It then retrieves its command-and-control (C2) infrastructure domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.

The ransomware module only activates on devices running Android 9 or older. Android 10's Scoped Storage feature significantly restricts encryption capability to the external-files directory, limiting the malware's effectiveness on newer versions. On vulnerable devices, Mantax Otax searches shared storage, encrypts targeted file types using a victim-specific AES key obtained from the C2 server, deletes the original files, and adds the '.enc' extension to encrypted copies. It also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.

The spyware capabilities include stealing lock-screen PINs to maintain persistent access, reading SMS and one-time passwords, accessing call logs, contacts, browsing history, app lists, Google account information, and location. Additionally, the malware can extract WhatsApp profiles and messages, as well as Telegram chats, using simulated interactions via Accessibility services. It also abuses Android's MediaProjection API to capture screenshots.

Zimperium researchers were able to exploit a misconfiguration in the Firebase C2 server, which exposed the attackers' chats with victims, according to the report.

§

Analysis

Why This Matters

  • Mantax Otax represents a growing trend of multi-function malware that combines data theft, file encryption, and harassment in a single package, increasing the potential harm to victims.
  • The malware specifically targets older Android devices (version 9 and earlier), which lack the Scoped Storage security feature introduced in Android 10, leaving a significant number of legacy devices vulnerable.
  • The abuse of Android's Accessibility service underscores how this legitimate feature continues to be exploited for malicious purposes, highlighting the need for stricter permissions controls.

Background

Android malware has evolved significantly over the past decade, with threat actors increasingly combining capabilities to maximize impact. Accessibility services, designed to help users with disabilities, have been frequently abused by malware to gain elevated control over devices since they can simulate user interactions and read screen content. Google has implemented restrictions over time, but older Android versions remain susceptible. The use of Firebase and GitHub for C2 communications is a common technique among mobile malware operators to avoid detection and maintain flexibility.

Key Perspectives

Affected users: Users on Android 9 or older face the highest risk, as the malware can fully encrypt their files and steal a wide range of personal data. Victims may lose important files and have their privacy compromised, including WhatsApp and Telegram messages. Android security ecosystem: The introduction of Scoped Storage in Android 10 provides effective protection against the ransomware module, but many users still run older versions. Google's Play Protect and other security measures may help block distribution through unofficial APKs, but sideloading remains a risk. Cybersecurity researchers: The misconfiguration in the Firebase C2 server that exposed attacker-victim communications demonstrates how researchers can gain valuable intelligence to disrupt operations. However, the discovery also highlights that attackers are using cloud infrastructure that may be difficult to take down unilaterally.

What to Watch

  • Whether the Mantax Otax operators expand their targeting to include Android 10+ devices through new techniques or exploit other vulnerabilities.
  • Distribution growth as the malware evolves and possibly appears on third-party app stores or messaging platforms.
  • Google's response, including potential Play Protect updates or Android security patch notes addressing the techniques used (Accessibility service abuse, Firebase misuse).

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.