Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Android Malware Combines Ransomware with Espionage

Android Malware Combines Ransomware with Espionage

Posted on September 11, 2026 By CWS

A recently identified Android malware, known as Mantax Otax, integrates ransomware capabilities with espionage, creating a significant threat for users who download apps from unverified sources. This malware not only locks files but also surveils the screen, intercepts one-time passwords (OTPs), and covertly activates the phone’s cameras, making it a dual threat of extortion and privacy invasion.

Malware Distribution and Impact

The Mantax Otax campaign primarily uses standalone Android app packages, or APKs, which are distributed via third-party file-sharing platforms. Victims are typically led to these malicious apps through shared links, messaging platforms, or phishing attempts, often convincing them to install the app outside of official app stores.

Research indicates that the malware’s activities are linked to Indonesian threat actors, with clues in the language and victim files pointing towards a focus on Indonesian targets. This discovery highlights the evolving tactics of mobile cybercriminals who are merging surveillance, account theft, and file encryption into a single malicious package.

Technical Functionality and Permissions

Once installed, Mantax Otax requests device-administrator rights and seeks permissions to access SMS, contacts, audio, and images. It also asks for Accessibility access, a legitimate Android feature, which it abuses to read screen content and perform actions, similar to the Crocodilus Android banking threat.

The malware operates on Android 9 and older versions by searching external storage for files to encrypt, replacing originals with encrypted versions marked by a .enc extension and displaying a ransom note. Android 10 and newer versions limit the damage due to Scoped Storage but do not eliminate surveillance risks. Attackers can negotiate ransomware demands through an on-screen chat.

Surveillance and Data Theft

Mantax Otax further exploits the MediaProjection function to capture screenshots, record videos, and stream display content in real time. Screenshots are uploaded to external sites, allowing operators to view and manipulate victims’ devices. The spyware can also activate the phone’s cameras to take photos without user interaction.

The malware collects extensive data, including contacts, call logs, browser history, location data, and more. It monitors notifications and SMS messages, endangering multi-factor authentication codes. Additionally, it targets messaging apps like WhatsApp and Telegram, posing significant account security risks.

Preventive Measures and Recommendations

Users are advised to avoid downloading APKs from unsolicited messages or unfamiliar links and to use trusted app stores. They should be cautious of granting permissions that don’t align with an app’s purpose, particularly Accessibility, administrator, SMS, screen-capture, or camera permissions.

Organizations should monitor for sideloaded apps, unusual Accessibility activity, and unexpected outbound traffic on managed devices. Any signs of unfamiliar lock screens or unexpected permission requests should prompt users to disconnect from networks and seek professional support.

Maintaining awareness of active malware and phishing threats is crucial for cybersecurity teams. Utilizing tools like ANYRUN can enhance early detection and prevent incidents.

Cyber Security News Tags:Android malware, APK files, Cybersecurity, data breach, Espionage, Mantax Otax, mobile security, OTP theft, Ransomware, Threat Actors

Post navigation

Previous Post: Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
Next Post: Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel

Related Posts

New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users Cyber Security News
Chinese Hackers Exploit Microsoft Exchange Servers to Steal COVID-19 Research Data Chinese Hackers Exploit Microsoft Exchange Servers to Steal COVID-19 Research Data Cyber Security News
BlueHammer Exploit Affects Windows Defender Security BlueHammer Exploit Affects Windows Defender Security Cyber Security News
Google Launches Ransomware Protection for Drive Google Launches Ransomware Protection for Drive Cyber Security News
Apache Tomcat Coyote Vulnerability Let Attackers Trigger DoS Attack Apache Tomcat Coyote Vulnerability Let Attackers Trigger DoS Attack Cyber Security News
Leading Server Security Solutions for 2026 Leading Server Security Solutions for 2026 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark