°C
Air:
GOLD73,245 0.25%
SILVER84,520 0.29%
USD83.25 0.12%
EUR90.45 0.08%
GBP105.6 0.15%
New Android Malware Mantax Otax Can Steal OTPs and Access WhatsApp Chats
Cyber Security

New Android Malware Mantax Otax Can Steal OTPs and Access WhatsApp Chats

0 views
Text Size:

Android users are being warned about a newly identified malware strain called Mantax Otax, which combines spyware, ransomware and remote control capabilities in a single malicious application.

Android users are being warned about a newly identified malware strain called Mantax Otax, which combines spyware, ransomware and remote control capabilities in a single malicious application.

The malware was identified by researchers at Zimperium's zLabs security research team. According to the researchers, Mantax Otax is designed to collect sensitive information from compromised Android devices while also providing attackers with the ability to interfere with the device and encrypt files. The campaign has been linked to threat actors operating from Indonesia, although the discovery does not mean that the malware is necessarily limited to users in that country.

One of the major concerns surrounding Mantax Otax is the way it can obtain access to an infected smartphone. Security researchers found samples being distributed as Android APK files through third party file sharing services rather than through the official Google Play Store. The malware can also be promoted through phishing messages, social engineering and other methods that persuade users to download and manually install an application.

After installation, Mantax Otax requests powerful permissions from the device. These include Accessibility access and device administrator privileges. Android Accessibility is a legitimate feature designed to assist users with disabilities, but malware can abuse the permission to interact with applications, read information displayed on the screen and perform certain actions on behalf of the user.

The malware's information stealing capabilities are particularly concerning because researchers found that it can collect SMS messages and one time passwords. OTPs are commonly used as an additional security step when users sign in to banking services, email accounts, social media platforms and other online services. If an attacker obtains an OTP together with other stolen credentials, the information could potentially be used in attempts to compromise an account.

Mantax Otax can also target communication applications. Researchers reported that the malware can obtain WhatsApp profile information and messages as well as Telegram chats by abusing Android's Accessibility functionality. This means an infected device could potentially expose private communications without the user's knowledge.

The malware is not limited to messages and OTPs. According to the security research, Mantax Otax can collect contacts, call logs, browser history, installed application information, location data, device details and information associated with Google accounts. It can also capture screenshots and record activity on the device.

Researchers found that the malware can abuse Android's MediaProjection functionality to capture the screen. It can reportedly record the screen as video and transmit information to infrastructure controlled by the attackers. The malware can also use the device's camera to take photographs without the user's normal interaction.

Another feature that raises security concerns is the malware's ability to interfere with the device's lock screen. Researchers reported that Mantax Otax can display a fake locking interface and attempt to capture the PIN entered by the victim. This can provide attackers with another method of obtaining authentication information.

Mantax Otax also includes a ransomware component. Researchers found that the malware can search for files and encrypt selected data using a victim specific encryption key. The affected files can receive an additional file extension after encryption, potentially preventing the victim from accessing important documents, photographs and other data.

However, the ransomware capability is more limited on newer Android versions. Research indicates that the file encryption component has a greater impact on devices running Android 9 or older. Android 10 and later introduced stronger storage restrictions through Scoped Storage, which can limit the malware's ability to access files outside its own application environment. This does not mean that newer Android devices are completely protected, because the spyware and information stealing functions can still present a security risk.

Researchers also identified a second version of Mantax Otax with additional features intended to disrupt and intimidate victims. These reportedly include full screen content, pop up messages, unexpected images and audio features. Such capabilities can make the infected device difficult to use and increase pressure on victims during a ransomware attack.

The discovery highlights the risks associated with downloading applications from unofficial sources. Users are often encouraged to install APK files through links shared in messages, websites or social media posts. While APK files are a legitimate Android application format, installing them from untrusted sources can bypass some of the protections provided by official application distribution channels.

Security experts recommend that Android users avoid installing applications from unknown websites or suspicious links. Users should also carefully examine permission requests, particularly when an application unexpectedly asks for Accessibility access, device administrator privileges or other powerful permissions.

Keeping Android devices and applications updated can also reduce exposure to known security weaknesses. Users should maintain security protections such as Google Play Protect and avoid disabling security features simply to install an application.

Anyone who suspects that a device has been infected should avoid entering passwords, banking credentials or OTPs until the device has been checked. Users should consider disconnecting the affected device from networks and seek assistance from a trusted cybersecurity professional or official device support service.

Mantax Otax demonstrates how modern mobile malware can combine several threats in one package. Instead of focusing only on stealing information or encrypting files, the malware reportedly combines surveillance, credential theft, remote control and ransomware capabilities.

The discovery does not mean that every Android user is automatically infected or that WhatsApp itself has been compromised. The reported infection route involves malicious applications and social engineering designed to persuade users to install the malware. Therefore, avoiding suspicious APK files and carefully reviewing application permissions remain important steps for reducing the risk.

The campaign has been linked to threat actors operating from Indonesia, although the discovery does not mean that the malware is necessarily limited to users in that country.