$ techbeacon▋
Ransomware

Hybrid Android Threat ‘Mantax Otax’ Marries Ransomware With Spyware, Researchers Warn

Hybrid Android Threat ‘Mantax Otax’ Marries Ransomware With Spyware, Researchers Warn

Security analysts have uncovered a new Android‑focused malware family named Mantax Otax that blends the destructive power of ransomware with the data‑harvesting traits of spyware. The code first surfaced in recent weeks and is capable of locking users out of their own files while simultaneously siphoning personal information and turning infected devices into tools for unsolicited messaging.

Once installed, Mantax Otax encrypts a broad range of file types using a strong cipher, then displays a ransom note demanding payment for the decryption key. In parallel, the program scans the device for contacts, messages, photos, location data and authentication tokens, quietly transmitting the collected material to remote servers under the attacker’s control.

Early analysis suggests the strain is distributed through malicious applications that evade Google Play’s vetting process, often appearing on third‑party app stores or being delivered via phishing links that masquerade as legitimate software updates. The dual‑function design marks a shift from earlier Android ransomware, which typically focused solely on extortion, to a more versatile threat capable of both financial gain and ongoing espionage.

The emergence of Mantax Otax is significant because it demonstrates a growing sophistication among mobile‑focused threat actors. Smartphones now store a wealth of personal and corporate data, making them attractive targets for attackers seeking both immediate ransom payouts and long‑term intelligence collection. By coupling file encryption with covert data exfiltration, the malware raises the stakes for users and enterprises that rely on Android devices for daily operations.

Experts advise users to keep their operating systems and applications up to date, restrict installations to the official Google Play Store, and consider reputable mobile security solutions that can detect anomalous behavior. Regular backups of important files remain a critical defense against ransomware, while vigilance against suspicious links can reduce the risk of initial infection. Law‑enforcement agencies are reportedly monitoring the threat, and security firms continue to share indicators of compromise to help mitigate the spread of this hybrid Android menace.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related