Skip to content
Tech News
← Back to articles

New Android malware encrypts files, steals data, and harasses victims

read original get Bitdefender Mobile Security for Android → more articles
Why This Matters

Mantax Otax blurs the line between mobile ransomware and spyware, showing that Android threats are getting more aggressive and personal, including harassment and in-app ransom negotiation. It underscores the real-world risk of sideloading APKs from outside Google Play and of running outdated Android versions, since the file-encryption module only works on Android 9 and earlier.

Key Takeaways
Worth a Look

Bitdefender Mobile Security for Android — With Android malware like Mantax Otax spreading through sideloaded APKs and phishing links, an on-device security app adds a layer of scanning and web protection Google Play alone won't give you. Bitdefender Mobile Security is a well-known subscription key card that installs in minutes and watches apps and links for malicious behavior.

See Bitdefender Mobile Security for Android on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.

After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.

Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.

According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android’s official app store, using phishing and social engineering messages to target victims.

Encrypting older Androids

According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.

The malware then deletes the original files and adds the ‘.enc’ extension to the encrypted copies.

Mantax Otax also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.

Replacing users' images (left) with ransom notes (right)

... continue reading