BlackTree Security · Infrastructure · Automation · AI

BlackTree — Independent Technology Analysis

BlackTree Editorial

Independent technology intelligence Analysis · Technical guides · Homelab · Legacy systems

Security, systems and emerging technology

Know the signal behind the incident.

Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Evidence-linked Operational context Independent

Researchers Heard Headphone Audio From 30 Metres Away Without Hacking Bluetooth

InjectEave researchers recovered headphone audio through induced electromagnetic leakage from as far as 30 metres in a controlled test. What the experiment does and does not…

Read the article

Current reporting

Latest intelligence

View all articles ↗

This Android Ransomware Can Watch Your Screen While Demanding Payment

The ransom message is the most visible part of Mantax Otax, but it may not be the most damaging. Researchers say the Android malware can monitor a device's screen, read messages and collect other personal data while also trying to lock files and demand payment. That combination changes the response question from 'Can we restore the files?' to 'What did this phone reveal before anyone noticed?'

Zimperium's 9 September analysis describes two versions of Mantax Otax. The page provides no publication time. Some analysed samples were hosted as standalone APK files on a third-party sharing service, suggesting manual installation through a link rather than ordinary app-store delivery. The research does not establish how every infection began, how many people were affected or that the malware was distributed through Google Play. Language and recovered files point towards targets in Indonesia; they do not by themselves establish the nationality of an operator.

After installation, the app asks for device-administrator privileges and sensitive permissions, then requests Android accessibility access. If a person grants those requests, the malware can reach far beyond the files it aims to encrypt. BlackTree has documented similar abuse of Android Accessibility by ToxicPanda 2.0, though these are distinct malware families. Zimperium reports code and observed behaviour for collecting contacts, call logs, SMS messages, browser history, media and information about installed apps. It also describes interception of lock-screen PIN entry and access to messaging content through accessibility features.

Screen capture is a separate path. The malware uses Android's MediaProjection interface…

16 Sep 2026 · 4 min read

AVEVA’s Patch Cannot Secure the Files You Forgot

A patch can close a software flaw without making the files it used to protect safe. That is the uncomfortable detail in the new AVEVA Pipeline Integrity Monitor bulletin. The vendor has…

16 Sep 2026 · 4 min read

A $4 Lost-Phone Report Could Silence Your Home Alarm

The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft…

16 Sep 2026 · 4 min read

Revised reporting

Recently updated

View all articles

Geographic context

Regional intelligence

Browse all articles ↗

Coverage leaders

Vendor intelligence

Browse all articles ↗

Practical archive

Lab &
Legacy

Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.