LmCast :: Stay tuned in

New Android malware encrypts files, steals data, and harasses victims

Recorded: Sept. 10, 2026, 10:08 p.m.

Original Summarized

New Android malware encrypts files, steals data, and harasses victims

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

New Android malware encrypts files, steals data, and harasses victims

September Windows Server updates break Remote Desktop Services

Surfshark VPN says hackers breached internal testing, proxy servers

Microsoft Excel KB5002914 update breaks copy and paste for some users

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityNew Android malware encrypts files, steals data, and harasses victims

New Android malware encrypts files, steals data, and harasses victims

By Bill Toulas

September 10, 2026
05:40 PM
0

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.
Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.
After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.
Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.
According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android’s official app store, using phishing and social engineering messages to target victims.
Encrypting older Androids
According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.
The malware then deletes the original files and adds the ‘.enc’ extension to the encrypted copies.
Mantax Otax also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.

Replacing users' images (left) with ransom notes (right)Source: Zimperium
Zimperium researchers were able to exploit a misconfiguration in the Firebase C2 server, which exposed the attackers’ chats with victims.

Firebase chat (left) and leaked comms (right)Source: Zimperium
Mantax Otax’s ransomware module only runs against Android devices running version 9 or older, as the ‘Scoped Storage’ security and privacy feature in Android 10 and later significantly restricts the encryption capability to the external-files directory.
Spying, spamming, and harassing
Apart from ransomware, Mantax Otax includes spyware, remote control, and harassment features.
The researchers note that the malware can steal lock-screen PINs to maintain persistent access, read SMS and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location.

Overlays that steal lock-screen PINsSource: Zimperium
It can also extract WhatsApp profiles and messages, as well as Telegram chats, using simulated interactions via Accessibility services.
Additionally, it abuses Android’s MediaProjection API to capture screenshots, record MP4 videos, and stream the victim’s screen in near real time via the Catbox file hosting service.
Mantax Otax can also capture photographs using the infected device’s cameras and upload them to the operator.
Version 2 of the malware added harassment functions such as repeated dialog boxes, full-screen videos, rapid “jumpscare” image overlays, and remotely controlled text-to-speech messages played through the device speakers.
These additional features add an intimidation component to the attacks, which act as a pressure mechanism for the victim to pay the ransom.
Because Zimperium is a Google security partner via the App Defense Alliance (ADA), Mantax Otax is already detected and blocked by up-to-date Android devices with an active Play Protect service.
Users are generally advised not to install APKs from outside Google Play, not to give questionable apps Accessibility permissions, and to only trust reputable publishers.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Android 17 adds ECH support to make web browsing harder to trackToxicPanda Android malware uses VPN permissions to block Google PlayNew Manic Android malware can exfiltrate data through nearby devicesAndroid malware combo takes out loans and relays victims' credit cardsWest Pharmaceutical says hackers stole data, encrypted systems

Android
Encryption
Mantax Otax
Mobile
Ransomware

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A new Android malware strain named Mantax Otax has emerged, which integrates both ransomware and spyware capabilities to encrypt files, exfiltrate sensitive data, and harass victims. Indonesian operators distribute this malware through malicious APKs hosted outside the official Google Play store, employing phishing and social engineering tactics to lure users. Upon installation, the malware seeks to gain extensive control over the compromised device by requesting permission to use the Accessibility service. This access allows the malware to retrieve its command-and-control infrastructure domain from GitHub and transmit victim details, including location, carrier, Android version, and device identifiers, back to the operators, with commands often relayed through Firebase or WebSockets.

The ransomware module specifically targets Android devices running version 9 or older, as the modern Scoped Storage security features in Android 10 and later restrict file encryption capabilities to the external files directory. Mantax Otax operates by searching shared storage, encrypting targeted file types using a unique AES key obtained from the C2 server, deleting the original files, and appending the extension .enc to the encrypted copies. Furthermore, the malware replaces local images with ransom notices and initiates a full-screen chat on Firebase to facilitate ransom negotiations. Researchers from Zimperium discovered a misconfiguration in the Firebase C2 server, which inadvertently exposed the chat communications between the attackers and the victims.

Beyond encryption, Mantax Otax functions as a spyware tool, incorporating capabilities for surveillance, data exfiltration, and harassment. The malware can steal sensitive information such as lock-screen PINs to maintain persistent access, read SMS and one-time passwords, access call logs, contacts, browsing history, application lists, Google account information, and geographical location. It leverages the Accessibility services to simulate interactions, enabling the extraction of profiles and messages from applications like WhatsApp and Telegram. Moreover, the malware exploits Android’s MediaProjection API to capture screenshots, record video files, and stream the victim's screen in real time via a file hosting service like Catbox. The malware can also access the device's camera to capture photographs and upload them to the operators.

Version two of the malware introduced explicit harassment features designed to intensify the pressure on victims to pay the ransom. These features include the display of repeated dialog boxes, full-screen videos, rapid image overlays known as jump scares, and remotely controlled text-to-speech messages played through the device speakers, which serve as an intimidation mechanism. Zimperium noted that this malware is already detected and blocked by updated Android devices with active Play Protect services. Consequently, security guidance advises users against installing APKs from sources outside Google Play, cautioning against granting Accessibility permissions to untrusted applications, and emphasizing the need to trust only reputable publishers.