New Android malware encrypts files, steals data, and harasses victims

New Android malware encrypts files, steals data, and harasses victims
Mantax Otax is a new Android threat that blends ransomware and spyware to encrypt files, steal sensitive information, and harass victims. Indonesian operators spread it through malicious APKs outside Google Play, while the malware abuses Accessibility permissions, Firebase, and other services to control devices and exfiltrate data. #MantaxOtax #GooglePlay #Firebase #AccessibilityService

Keypoints

  • Mantax Otax combines ransomware, spyware, remote control, and harassment features.
  • Indonesian operators distribute it through malicious APKs and phishing messages.
  • The malware abuses Accessibility permissions and fetches C2 instructions from GitHub, Firebase, or WebSockets.
  • It targets older Android versions to encrypt files, replace images with ransom notes, and delete originals.
  • It can steal PINs, SMS, OTPs, chats, screenshots, photos, and other sensitive device data.

Read More: https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/