A recently identified Android malware, known as Mantax Otax, integrates ransomware capabilities with espionage, creating a significant threat for users who download apps from unverified sources. This malware not only locks files but also surveils the screen, intercepts one-time passwords (OTPs), and covertly activates the phone’s cameras, making it a dual threat of extortion and privacy invasion.
Malware Distribution and Impact
The Mantax Otax campaign primarily uses standalone Android app packages, or APKs, which are distributed via third-party file-sharing platforms. Victims are typically led to these malicious apps through shared links, messaging platforms, or phishing attempts, often convincing them to install the app outside of official app stores.
Research indicates that the malware’s activities are linked to Indonesian threat actors, with clues in the language and victim files pointing towards a focus on Indonesian targets. This discovery highlights the evolving tactics of mobile cybercriminals who are merging surveillance, account theft, and file encryption into a single malicious package.
Technical Functionality and Permissions
Once installed, Mantax Otax requests device-administrator rights and seeks permissions to access SMS, contacts, audio, and images. It also asks for Accessibility access, a legitimate Android feature, which it abuses to read screen content and perform actions, similar to the Crocodilus Android banking threat.
The malware operates on Android 9 and older versions by searching external storage for files to encrypt, replacing originals with encrypted versions marked by a .enc extension and displaying a ransom note. Android 10 and newer versions limit the damage due to Scoped Storage but do not eliminate surveillance risks. Attackers can negotiate ransomware demands through an on-screen chat.
Surveillance and Data Theft
Mantax Otax further exploits the MediaProjection function to capture screenshots, record videos, and stream display content in real time. Screenshots are uploaded to external sites, allowing operators to view and manipulate victims’ devices. The spyware can also activate the phone’s cameras to take photos without user interaction.
The malware collects extensive data, including contacts, call logs, browser history, location data, and more. It monitors notifications and SMS messages, endangering multi-factor authentication codes. Additionally, it targets messaging apps like WhatsApp and Telegram, posing significant account security risks.
Preventive Measures and Recommendations
Users are advised to avoid downloading APKs from unsolicited messages or unfamiliar links and to use trusted app stores. They should be cautious of granting permissions that don’t align with an app’s purpose, particularly Accessibility, administrator, SMS, screen-capture, or camera permissions.
Organizations should monitor for sideloaded apps, unusual Accessibility activity, and unexpected outbound traffic on managed devices. Any signs of unfamiliar lock screens or unexpected permission requests should prompt users to disconnect from networks and seek professional support.
Maintaining awareness of active malware and phishing threats is crucial for cybersecurity teams. Utilizing tools like ANYRUN can enhance early detection and prevent incidents.
