logo

MantaxOtax Android Malware Combines Ransomware With Spyware

ID: 537dcd9b-606b-58a3-bd5a-51bf5d416dba

STIX ID: report--537dcd9b-606b-58a3-bd5a-51bf5d416dba

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

...
...

MantaxOtax is an Android malware family that fuses file-encrypting ransomware with extensive spyware and remote-control features: it requests device-admin and Accessibility permissions, encrypts or overwrites user files (depending on Android version), intercepts PINs and OTPs, harvests messages and account data, abuses MediaProjection for screen capture/streaming, and uses GitHub-resolved C2 and Firebase for communications; Zimperium links samples to Indonesian threat actors and notes distribution via sideloading and server misconfigurations exposing extortion dialogs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.