Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Meta’s Muse AI works and creeps me out

    September 11, 2026

    OpenAI Launches the Agents API in Public Beta, Putting the Codex Harness Behind One API Call

    September 11, 2026

    New Android malware encrypts files, steals data, and harasses victims

    September 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meta’s Muse AI works and creeps me out
    • OpenAI Launches the Agents API in Public Beta, Putting the Codex Harness Behind One API Call
    • New Android malware encrypts files, steals data, and harasses victims
    • A wallet coding flaw just helped shut down an entire XRP project
    • As saltwater advances, Gambian farmers rethink how to protect rice fields
    • Text Us Your Dominican Baseball Story on WhatsApp — ProPublica
    • Yemen’s Iran-backed Houthi rebels seize strategic Red Sea port city of Mocha
    • Schools are catching on to Big Tech’s playbook
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Android malware encrypts files, steals data, and harasses victims

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 11, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

    Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages.

    After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices.

    Next, it retrieves its command-and-control infrastructure (C2) domain from GitHub and sends back victim details such as location, carrier, Android version, and device ID. The C2 may send commands through Firebase or WebSockets for execution.

    According to Zimperium, Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, Android’s official app store, using phishing and social engineering messages to target victims.

    Encrypting older Androids

    According to mobile security company Zimperium, Mantax Otax encrypts devices running older Android versions. It searches shared storage and encrypts targeted file types using a victim-specific AES key obtained from the C2 server.

    The malware then deletes the original files and adds the ‘.enc’ extension to the encrypted copies.

    Mantax Otax also replaces local images with ransom notices and opens a full-screen Firebase-hosted chat to facilitate ransom payment negotiations.

    Replacing user's images (left) with ransom notes (right)
    Replacing users’ images (left) with ransom notes (right)
    Source: Zimperium

    Zimperium researchers were able to exploit a misconfiguration in the Firebase C2 server, which exposed the attackers’ chats with victims.

    Firebase chat (left) and leaked comms (right)
    Firebase chat (left) and leaked comms (right)
    Source: Zimperium

    Mantax Otax’s ransomware module only runs against Android devices running version 9 or older, as the ‘Scoped Storage’ security and privacy feature in Android 10 and later significantly restricts the encryption capability to the external-files directory.

    Spying, spamming, and harassing

    Apart from ransomware, Mantax Otax includes spyware, remote control, and harassment features.

    The researchers note that the malware can steal lock-screen PINs to maintain persistent access, read SMS and one-time passwords, access call logs, contacts, browsing history, app lists, Google account information, and location.

    Overlays that steal lock-screen PINs
    Overlays that steal lock-screen PINs
    Source: Zimperium

    It can also extract WhatsApp profiles and messages, as well as Telegram chats, using simulated interactions via Accessibility services.

    Additionally, it abuses Android’s MediaProjection API to capture screenshots, record MP4 videos, and stream the victim’s screen in near real time via the Catbox file hosting service.

    Mantax Otax can also capture photographs using the infected device’s cameras and upload them to the operator.

    Version 2 of the malware added harassment functions such as repeated dialog boxes, full-screen videos, rapid “jumpscare” image overlays, and remotely controlled text-to-speech messages played through the device speakers.

    These additional features add an intimidation component to the attacks, which act as a pressure mechanism for the victim to pay the ransom.

    Because Zimperium is a Google security partner via the App Defense Alliance (ADA), Mantax Otax is already detected and blocked by up-to-date Android devices with an active Play Protect service.

    Users are generally advised not to install APKs from outside Google Play, not to give questionable apps Accessibility permissions, and to only trust reputable publishers.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Android data encrypts Files harasses Malware Steals Victims
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical NetScaler Vulnerability Exploited in Attacks

    Trezor Reveals Another Data Breach

    Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Mandiant Founder Kevin Mandia Joins Amazon Board

    ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Meta’s Muse AI works and creeps me out

    September 11, 2026

    OpenAI Launches the Agents API in Public Beta, Putting the Codex Harness Behind One API Call

    September 11, 2026

    New Android malware encrypts files, steals data, and harasses victims

    September 11, 2026

    A wallet coding flaw just helped shut down an entire XRP project

    September 11, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Meta’s Muse AI works and creeps me out

    September 11, 2026

    OpenAI Launches the Agents API in Public Beta, Putting the Codex Harness Behind One API Call

    September 11, 2026

    New Android malware encrypts files, steals data, and harasses victims

    September 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.