• A new Android attack combines malware and ransomware in a cocktai

    From TechnologyDaily@1337:1/100 to All on Fri Sep 11 14:15:21 2026
    A new Android attack combines malware and ransomware in a cocktail of cybercrime

    Date:
    Fri, 11 Sep 2026 13:05:00 +0000

    Description:
    Unique malware variant spotted targeting Android users, taking photos with victim cameras before deploying an encryptor.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Zimperium uncovers Mantax Otax, Android malware merging infostealer, RAT, backdoor, and ransomware
    Distributed via APKs on thirdparty stores, social media, and phishing; older Android versions most at risk Steals extensive data, enables remote monitoring, then encrypts files with AES and demands ransom When threat
    actors target peoples devices, they usually infect it with one of many
    malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor.

    Rarely do we see all of these functionalities merged into a single entity,
    and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that. Mantax Otax The security outfit published an in-depth report on Mantax Otax , a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we dont know exactly how many people are infected, or if this campaign is aimed primarily at business
    users, or individuals in general. Latest Videos From TechRadar Watch full video here:

    The malware is being distributed as a standalone APK, meaning it can be found on third-party app stores, Telegram channels, forums, and across social
    media. There are no traces of Mantax Otax on any of the official app repositories, including the Google Play Store, or Samsung s Galaxy Store. Zimperium also speculates that it is likely being distributed via phishing emails.

    Mantax Otax primarily targets users sporting older Android phones . Versions
    9 and older are most at risk, since on these devices the attackers can make use of all of the malwares features. Android 10 and newer models do get some protection: You may like Hundreds of Android banking and crypto apps hit by dangerous new Rokarolla malware Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes DeepSeek accidentally built a working ransomware strain

    Conversely, on modern devices running Android 10 and above, the malwares efficacy is severely hindered by native OS defenses, specifically Scoped Storage restrictions, the researchers explained. Due to these sandboxing rules, the ransomware is constrained to scanning only the application's localized external files directory, which drastically mitigates the blast radius and reduces the volume of accessible user files.

    Newer devices, as well as users of Zimperiums Mobile Threat Defense (MTD) and Runtime Application Protection (zDefend) are said to be protected on a software level. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    Another important caveat is the permissions. As is usual on Android devices, most malware wont work unless the user grants an extensive set of permissions beforehand. In this case, Mantax Otax first asks for admin privileges, after which it grants itself an extensive list of capabilities, from accessing SMS messages, to contacts, audio, and images.

    It then requests accessibility permissions, fully taking over the compromised device. Malicious capabilities Mantax Otax is said to be quite capable. It steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data, and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can also pull lock-screen PINs. What to read next This Android banking trojan uses a fake VPN prompt to silence Google's defenses NordVPN warns of fake Ryanair, Emirates, Qatar Airways websites used to spread malware This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target

    Infostealing features aside, it also serves as a remote monitoring tool, grabbing screenshots, recording the screen, or livestreaming it directly to the attackers. It can take photos using both the front and rear cameras, although Zimperium did not mention any microphone-recording capabilities.

    Finally, once all of the data has been harvested, it encrypts user files with AES, deletes the originals, and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers directly and negotiate a ransom payment in exchange for getting their device back.

    The tool seems to be in continuous development. Zimperium found two separate versions, one being an evolution of the other: Notably, it has modified its network traffic behavior to utilize WebSockets and introduced a set of new commands, the researchers said.

    There is a reason why ransomware operators prefer targeting businesses
    instead of individuals. Although the latter has not disappeared entirely from the victim list, businesses stand to lose a lot more from disrupted
    operations and, as such, are targeted more frequently. Unfortunately, we dont know what kind of app Mantax Otax is spoofing, therefore it is difficult to assess who the targets are. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/a-new-android-attack-combines-malware-a nd-ransomware-in-a-cocktail-of-cybercrime


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)