Researchers warn about new Android malware that can steal OTPs, spy on WhatsApp and harass victims
A new Android malware called Mantax Otax is reportedly stealing OTPs, snooping on WhatsApp and Telegram, encrypting files on older phones and even tormenting victims with jumpscares, pop-ups and creepy audio.
by Divya Bhati · India TodayIn Short
- Indonesian operators spread malicious APKs through phishing links and sideloading campaigns
- After installation, attackers gain broad control using admin and Accessibility permissions
- Older Android phones can have files encrypted with victim-specific AES keys
Android users beware! Researchers have found a new malware called Mantax Otax that can steal OTPs, spy on WhatsApp and Telegram chats, lock victims out of their Android phones and even harass them with disturbing pop-ups, videos and audio. This dangerous malware is reportedly being spread through malicious APK files outside Google Play, so users are asked to take high caution.
The malware was discovered by mobile security firm Zimperium, and is said to be anything but a typical Android threat. According to the researchers, Mantax Otax combines ransomware, spyware and remote-control capabilities, giving attackers several ways to take control of an infected phone.
Researchers found samples of Mantax Otax being distributed as malicious APK files hosted on third-party file-sharing platforms rather than Google Play. The malware was also found being spread through phishing links, messaging platforms and social-engineering campaigns, where users are tricked into downloading and installing the app.
Once installed, Mantax Otax asks for powerful permissions, including Accessibility access and device administrator privileges. With these permissions, the malware can reportedly interact with the device and carry out actions on the victim's behalf. It then connects to infrastructure controlled by the attackers and registers the infected device, sending back details such as its Android version, location and other device information. In simpler terms, the malware can hack the victims and perform actions without the user's knowledge.
Malware can steal OTPs and spy on WhatsApp
Researchers warn that the spyware side of Mantax Otax is particularly concerning. According to the report, the malware can read SMS notifications, including messages containing one-time passwords (OTPs), as well as collect call logs, contacts, browser history, installed apps, location information and Google account details.
It also targets chat apps. By misusing Android's Accessibility settings to pretend to be the user, Mantax Otax can steal WhatsApp profile details and messages, as well as Telegram chats. This means an infected phone can leak private conversations without the user knowing.
Not just that. Researchers found that the malware can do even more damage. It uses Android's MediaProjection feature to take screenshots, record the screen, and stream live activity from the device. It can also secretly take photos with the front or back camera and send them to the attackers.
But the malware does not stop at hacking the phone. Zimperium found that Mantax Otax v2 comes with several features designed to disturb and intimidate victims. It can repeatedly throw pop-up dialogues on the screen, display full-screen videos and sudden jumpscare-style images, and remotely trigger text-to-speech messages through the phone's speakers. The newer version can also block access to the screen and instruct victims to contact an "administrator".
Which Android phones are at risk?
According to researchers, the ransomware side of Mantax Otax mainly affects older Android phones running Android 9 or earlier, where it can access shared storage and encrypt photos, videos, documents and other files. On Android 10 and newer, storage restrictions limit its ability to access files, making the ransomware component less effective. However, newer phones are still vulnerable to the malware's spyware features.
As for where it is spreading, researchers found signs that the operators are targeting Indonesian users, but there is no indication that Mantax Otax is limited to Indonesia. Users elsewhere could also be at risk if they download and install the malicious APK.
How to stay safe from Mantax Otax
To stay safe, Android users should avoid installing APKs from unknown websites or message links and be wary of apps asking for Accessibility or device administrator access. Zimperium says Mantax Otax is detected by Google Play Protect, so keeping it enabled and the phone updated can help stay protected.
- Ends