New Android Malware Combines Ransomware and Spyware Capabilities
Share
Researchers at Zimperium’s zLabs team have identified a sophisticated Android malware named MantaxOtax that integrates ransomware with intensive spyware capabilities. The threat, which is linked to Indonesian threat actors, is reportedly distributed through sideloading via third-party file-sharing services.
MantaxOtax operates by requesting device administrator privileges and access to Android Accessibility services, providing attackers with broad control over device interactions. The malware’s command-and-control (C2) domains are resolved through a GitHub repository, a method that allows operators to switch to new infrastructure without changing the underlying code if a domain is blocked.
Surveillance and Data Theft
The spyware component is designed for extensive surveillance, collecting hardware details, location data, browser history, and call logs. It specifically targets communication apps by intercepting SMS messages—including one-time passwords (OTPs)—and using Accessibility services to extract WhatsApp profiles and messages, as well as Telegram credentials and chat histories.
Using the MediaProjection API, the malware can perform real-time screen recording, take screenshots, and capture silent photos via both device cameras. These captures are staged on the Catbox file host before being sent back to the operators.
Ransomware Mechanics and Device Locking
The ransomware functionality varies depending on the Android version. On devices running Android 9 or earlier, MantaxOtax performs a recursive scan of shared external storage and encrypts files using AES. On Android 10 and later, Scoped Storage limits the malware’s ability to encrypt files, confining the impact to the app’s own directory.
To facilitate extortion, the malware overwrites user images with ransom graphics and opens an on-screen chat interface for negotiations, which runs through Firebase. Some versions of the malware include more disruptive features, such as persistent screen locking, application blocking, and transparent overlays that swallow all touch input. Other variants use text-to-speech to play attacker messages aloud to harass the victim.




Leave a Reply