$ techbeacon▋
Ransomware

New Android Threat MantaxOtax Blends Ransomware Tactics with Spyware Surveillance

New Android Threat MantaxOtax Blends Ransomware Tactics with Spyware Surveillance

Security analysts have uncovered a novel Android threat called MantaxOtax that merges the destructive payoff model of ransomware with the data‑harvesting capabilities of spyware, marking a troubling evolution in mobile malware design.

The malware first encrypts files stored on the infected device, rendering photos, documents and app data inaccessible until a payment is made. Simultaneously, it activates a suite of surveillance tools that capture keystrokes, record voice calls, harvest SMS messages, and silently transmit contact lists and location data to remote servers controlled by the attackers.

Technical examinations reveal that MantaxOtax leverages Android’s accessibility services to gain elevated privileges without requiring root access. It also exploits a known flaw in the system’s intent handling to bypass security checks, allowing the malicious code to download additional payloads from a command‑and‑control infrastructure hosted on compromised cloud services.

The convergence of ransomware and spyware on a single platform is notable because most Android ransomware historically focused solely on extortion, while spyware families have traditionally avoided overt file‑encryption to stay hidden. By combining the two, MantaxOtax forces victims to choose between paying a ransom and risking exposure of personal information, a tactic that could increase the likelihood of successful extortion.

Experts warn that the threat could affect a broad range of users, from individuals who install apps from unofficial sources to enterprises that permit personal devices on corporate networks. The dual‑nature of the payload complicates remediation: removing the encryption layer does not erase the back‑door that continues to siphon data, and vice versa.

Infosecurity Magazine’s initial report has prompted cybersecurity firms to issue alerts and update mobile threat‑intel feeds. Users are advised to keep devices patched, avoid sideloading apps, and employ reputable mobile security solutions that can detect both ransomware behavior and unauthorized data exfiltration. Researchers anticipate that future malware may adopt similar hybrid approaches, underscoring the need for stronger defenses in the rapidly expanding Android ecosystem.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related