Particle.news

MantaxOtax Malware Blends Ransomware and Spyware on Android

This threat raises account-takeover risk by stealing OTPs and messages because operators can re-point control servers via GitHub.

Overview

  • Zimperium researchers disclosed MantaxOtax after finding malicious APKs that request device‑admin and Accessibility privileges and a misconfigured Firebase instance that exposed extortion chats and an apparent operator control-panel.
  • The ransomware module targets Android 9 and earlier by scanning shared external storage, fetching a device-specific AES key from its command server, encrypting files and leaving .enc copies, while Android 10 and later are largely protected by Scoped Storage.
  • Spyware and remote-control features abuse Accessibility and MediaProjection to read SMS including one-time passwords, capture WhatsApp and Telegram content, record or stream the screen, take photos with device cameras, and stage stolen media on third-party hosts.
  • Operators spread MantaxOtax through sideloaded APKs, phishing links and third-party file hosts, resolve live C2 domains from a GitHub repository so they can repoint infrastructure, and use Firebase or WebSockets for commands and extortion chats; a v2 adds persistent screen locks, overlays and jumpscare harassment to pressure victims.
  • Up-to-date devices with Play Protect are already detecting the strain, but users who install apps outside Google Play or grant powerful permissions remain vulnerable, so people should avoid unknown APKs, refuse Accessibility or device‑admin requests from untrusted apps, and keep Play Protect and the OS current to reduce fraud and account‑takeover risk.