BlackTree Security · Infrastructure · Automation · AI

This Android Ransomware Can Watch Your Screen While Demanding Payment

The ransom message is the most visible part of Mantax Otax, but it may not be the most damaging. Researchers say the Android malware can monitor a device’s screen, read messages and collect other personal data while also trying to lock files and demand payment. That combination changes the response question from ‘Can we restore the files?’ to ‘What did this phone reveal before anyone noticed?’

Zimperium’s 9 September analysis describes two versions of Mantax Otax. The page provides no publication time. Some analysed samples were hosted as standalone APK files on a third-party sharing service, suggesting manual installation through a link rather than ordinary app-store delivery. The research does not establish how every infection began, how many people were affected or that the malware was distributed through Google Play. Language and recovered files point towards targets in Indonesia; they do not by themselves establish the nationality of an operator.

How Mantax Otax turns permissions into several threats

After installation, the app asks for device-administrator privileges and sensitive permissions, then requests Android accessibility access. If a person grants those requests, the malware can reach far beyond the files it aims to encrypt. BlackTree has documented similar abuse of Android Accessibility by ToxicPanda 2.0, though these are distinct malware families. Zimperium reports code and observed behaviour for collecting contacts, call logs, SMS messages, browser history, media and information about installed apps. It also describes interception of lock-screen PIN entry and access to messaging content through accessibility features.

Screen capture is a separate path. The malware uses Android’s MediaProjection interface to take screenshots, record video and send screen content towards operator infrastructure. The researchers also describe camera capture and remote device-locking features. Those capabilities are not proof that every infected phone experienced every action. They show why looking only for encrypted files would give responders an incomplete picture.

The malware obtains an encryption key from its command-and-control service, targets common user-file types and presents an on-screen chat for payment demands. Zimperium found a newer version with additional screen-blocking and harassment features. Its report describes an exposed backend that let researchers observe extortion conversations, but it does not provide a reliable public count of confirmed victims. The vendor’s strong language about a sweeping campaign should not be mistaken for an established scale.

Newer Android changes the file risk, not the whole incident

One of the most important qualifications in the research concerns Android versions. On Android 9 and earlier, Zimperium says the malware can recursively traverse much of shared storage and encrypt a broad range of user files. Android 10 and later introduced scoped-storage restrictions that, in the researchers’ tests, constrained this encryption routine to the app’s own external-files directory. That is a substantial limit on the ransomware component.

It is not a blanket statement that a modern phone is safe from this malware. Permissions for accessibility, messages, screen recording and other sensitive functions create different exposures from general file storage. A phone might avoid widespread file encryption yet still leak communications or what appears on screen if those permissions were granted and the relevant routines ran. Organisations should assess the actual device and permissions rather than treating its Android version as a complete answer.

What users and defenders should do

Do not install an APK from an unsolicited message or file-sharing link because it claims to be a familiar app, update or support tool. Android’s warnings about sideloading and sensitive permissions are particularly relevant here. A request for accessibility, device-administrator status, SMS access or screen recording should be explainable by the app’s legitimate purpose. If it is not, stop and verify the source through a separate trusted channel.

For a suspected infection, isolate the phone from sensitive work and seek help using another device. Do not type banking credentials, one-time codes or a new password into the affected handset while its screen and messages may be monitored. Preserve evidence for incident response, then follow the organisation’s mobile-device recovery process. Changing exposed credentials and reviewing account sessions should happen from a known-clean device. Restoring files from a backup addresses encryption but not credentials or messages that may already have been copied.

Enterprise teams should check mobile-device policy for sideloaded apps, inventory devices running older Android releases, review unusual grants of accessibility and device-admin privileges, and look for relevant indicators using the researchers’ published indicator set. Indicators can change, so detections should also focus on behaviour such as unexpected screen capture, unusual permission escalation and unapproved APK installation.

Mantax Otax is a reminder that ‘ransomware’ can be an incomplete label. The file lock is an extortion device; the access granted to reach that point may enable a broader privacy and account-security incident. The public research supports that capability, while leaving the true number of infections and the operators’ identity unresolved.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *