This site uses cookies from Google to deliver its services and to analyze traffic. By visiting this site, you agree to the use of cookies. Learn More

PSA: This Android malware uses your phone to take covert photos

Mantax Otax is a newly-discovered type of Android malware. It combines ransomware and spyware, encrypts a phone’s data, steals sensitive information and then sends spam messages to its victims.

The malware was reported by BleepingComputer, a news site specialising in security issues. The perpetrators appear to be based in Indonesia. They distribute the malware via APK files hosted outside Google Play and specifically target users with phishing and social engineering messages. If a user installs the infected APK, it requests permission to use the accessibility service. This gives the malware comprehensive control over the infected device.

The malware then retrieves its command-and-control (C2) domain from GitHub and sends back details about the victim, such as location, mobile network provider, Android version and device ID. The C2 can send commands for execution via Firebase or WebSockets.

According to mobile security firm Zimperium, Mantax Otax encrypts devices running older versions of Android. The malware scans the shared storage and encrypts specific file types using a victim-specific AES key, which it receives from the C2 server.

The malware then deletes the original files and appends the file extension ‘.enc’ to the encrypted copies. Mantax Otax also replaces local images with ransom demands and opens a full-screen chat hosted by Firebase to facilitate negotiations regarding the ransom payment.

Apart from this encryption and the associated extortion, the malware causes further damage: it steals lockscreen PINs and reads text messages and one-time passwords. It also has access to call logs, contacts, browser history, app lists, WhatsApp messages, Google account information and location data. Furthermore, the malware can secretly take photos using your camera.

There is, however, some good news: the Mantax Otax ransomware module only works fully on Android devices running version 9 or older. Users running Android 10 or later, on the other hand, are largely protected. This is yet another example of the significant risk involved in using very old versions of Android. At this stage, however, the malware appears to be targeting users in Indonesia in particular.

How to protect yourself

Enable Google Play Protect. This Android virus scanner can detect Mantax Otax.

You should also avoid installing APK files from sources other than Google Play. Next, make sure you’ve installed the latest Android updates and have upgraded to the latest Android version, provided your device supports it. Android 17 is the newest generation available.

if your phone can’t install the latest updates then, bad news – it’s time for a new phone. That doesn’t mean you need to buy a brand-new 2026 model. An older generation or a refurbished phone that can still get the latest security updates will be good enough. For our top recommendations, see our round-ups of the best budget phones, the best mid-range phones and the best phones overall.



from Tech Advisor
via PSA: This Android malware uses your phone to take covert photos

Post a Comment

© RRAM - Education Galaxies. All Rights Reserved.