Home » Technology » Android » Mantax Otax: Android is hit by new super malware

Mantax Otax: Android is hit by new super malware

A new Android malware called Mantax Otax combines ransomware with extensive spying and remote control functions. The malware can encrypt files, access information and specifically intimidate or harass those affected.

Full force on old Android

After Declarations by security company Zimperium, Mantax Otax is distributed by operators from Indonesia via manipulated APK files offered outside the Google Play Store. Phishing messages and social engineering are used, among other things. Once installed, the malware requests access to Android accessibility features. This authorization allows the malware extensive control over the smartphone. She then obtains the address of her currently responsible command and control infrastructure from GitHub. The location, mobile phone provider, Android version and device ID, among other things, are then transmitted to the server. Commands can then be sent to the infected device via Firebase or WebSockets.

However, the ransomware function only targets older Android versions. Mantax Otax scans shared storage and encrypts specific file types with an individual AES key that it receives from the control server. The original files are then deleted, while the encrypted copies receive the “.enc” extension. In addition, the malware replaces existing images with ransom demands and opens a full-screen chat to negotiate with the attackers.

A misconfiguration of the Firebase server even allowed Zimperium researchers to view conversations between perpetrators and victims. The reason for the restriction to older devices lies in Android 10. With the introduction of Scoped Storage, apps’ access to external storage was significantly restricted. The encryption function of Mantax Otax is therefore only fully functional on Android 9 and older. So anyone who uses a reasonably current version of the operating system is only affected to a limited extent.

Comprehensive espionage

However, the malware also has extensive spying functions. It can intercept screen lock PINs, read SMS and one-time passwords, and steal call logs, contacts, browser data, installed apps, Google account information and location data. WhatsApp and Telegram content can also be accessed via simulated operating processes. With the MediaProjection interface, Mantax Otax can create screenshots and videos or broadcast the screen in near real time. It is also possible to take photos using the smartphone’s cameras. A second version of the malware was supplemented with aggressive intimidation features.

These include recurring dialogue windows, full-screen videos, suddenly displayed images and remote voiceovers. This is intended to create additional pressure so that those affected pay the ransom demanded. According to Zimperium, current Android devices with Play Protect activated already recognize and block Mantax Otax. However, users should not install APKs from unknown sources and in particular should not give suspicious apps access to the accessibility features.

Leave a Reply