New Android malware encrypts files, steals data, and harasses victims
Recorded: Sept. 10, 2026, 10:08 p.m.
| Original | Summarized |
New Android malware encrypts files, steals data, and harasses victims News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access New Android malware encrypts files, steals data, and harasses victims September Windows Server updates break Remote Desktop Services Surfshark VPN says hackers breached internal testing, proxy servers Microsoft Excel KB5002914 update breaks copy and paste for some users Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityNew Android malware encrypts files, steals data, and harasses victims New Android malware encrypts files, steals data, and harasses victims By Bill Toulas September 10, 2026 A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. Replacing users' images (left) with ransom notes (right)Source: Zimperium Firebase chat (left) and leaked comms (right)Source: Zimperium Overlays that steal lock-screen PINsSource: Zimperium Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Android Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
A new Android malware strain named Mantax Otax has emerged, which integrates both ransomware and spyware capabilities to encrypt files, exfiltrate sensitive data, and harass victims. Indonesian operators distribute this malware through malicious APKs hosted outside the official Google Play store, employing phishing and social engineering tactics to lure users. Upon installation, the malware seeks to gain extensive control over the compromised device by requesting permission to use the Accessibility service. This access allows the malware to retrieve its command-and-control infrastructure domain from GitHub and transmit victim details, including location, carrier, Android version, and device identifiers, back to the operators, with commands often relayed through Firebase or WebSockets. The ransomware module specifically targets Android devices running version 9 or older, as the modern Scoped Storage security features in Android 10 and later restrict file encryption capabilities to the external files directory. Mantax Otax operates by searching shared storage, encrypting targeted file types using a unique AES key obtained from the C2 server, deleting the original files, and appending the extension .enc to the encrypted copies. Furthermore, the malware replaces local images with ransom notices and initiates a full-screen chat on Firebase to facilitate ransom negotiations. Researchers from Zimperium discovered a misconfiguration in the Firebase C2 server, which inadvertently exposed the chat communications between the attackers and the victims. Beyond encryption, Mantax Otax functions as a spyware tool, incorporating capabilities for surveillance, data exfiltration, and harassment. The malware can steal sensitive information such as lock-screen PINs to maintain persistent access, read SMS and one-time passwords, access call logs, contacts, browsing history, application lists, Google account information, and geographical location. It leverages the Accessibility services to simulate interactions, enabling the extraction of profiles and messages from applications like WhatsApp and Telegram. Moreover, the malware exploits Android’s MediaProjection API to capture screenshots, record video files, and stream the victim's screen in real time via a file hosting service like Catbox. The malware can also access the device's camera to capture photographs and upload them to the operators. Version two of the malware introduced explicit harassment features designed to intensify the pressure on victims to pay the ransom. These features include the display of repeated dialog boxes, full-screen videos, rapid image overlays known as jump scares, and remotely controlled text-to-speech messages played through the device speakers, which serve as an intimidation mechanism. Zimperium noted that this malware is already detected and blocked by updated Android devices with active Play Protect services. Consequently, security guidance advises users against installing APKs from sources outside Google Play, cautioning against granting Accessibility permissions to untrusted applications, and emphasizing the need to trust only reputable publishers. |