A newly identified malware threat in the Android ecosystem, named Mantax Otax, combines ransomware with espionage capabilities. It targets users who install applications from untrustworthy sources, often through messaging apps or phishing attempts. The malware is linked to Indonesian cybercriminals and can steal sensitive information such as SMS one-time passwords, chat histories, and lock-screen PINs, facilitating account takeovers.
Mantax Otax requests device-administrator rights and seeks access to SMS messages, contacts, and media files. It encrypts files on devices running Android 9 and earlier using AES encryption and demands a ransom for recovery. Although the impact is reduced on Android 10 and later due to Scoped Storage, the malware still poses significant surveillance risks.
The malware collects extensive sensitive data, including contacts, call logs, and location data, and targets multi-factor authentication codes. It uses a deceptive system-lock overlay to capture PINs and has introduced features like WebSocket communications and disruptive pop-ups in its second iteration.
Users are advised to be cautious when installing applications, avoid unsolicited APKs, and reject permissions that do not align with an app's purpose. In case of suspicious activity, users should disconnect from networks and seek help before entering sensitive information. Organizations should monitor for signs of this malware on managed devices.