Mantax Otax Android Malware Mixes Spyware, Ransomware | #ransomware | #cybercrime


A new Android malware can combine ransomware and spyware while tormenting victims until they pay up.

Security researchers at Zimperium discovered the malware, dubbed Mantax Otax, which gives attackers several ways to exploit a single compromised device. Researchers found it can collect SMS messages, including one-time passwords, interact with WhatsApp and Telegram, capture screens and photos, and gather information about the device and its user.

Its ransomware capability gives attackers another pressure point. Zimperium found that the malware can encrypt files on devices running Android 9 or earlier, while scoped storage on Android 10 and later sharply limits the files it can reach. However, newer devices may still be exposed to its surveillance, credential theft, and screen-blocking capabilities.

Some samples analyzed by Zimperium were distributed as malicious APKs through a third-party file-sharing service. The researchers said this suggests attackers use phishing and social engineering to persuade victims to install the malware and approve powerful permissions. Researchers have linked the observed operation to Indonesian threat actors.

Inside the modus operandi of the multifaceted Android malware

Mantax Otax starts like many Android malware attacks: with a victim being tricked into installing a malicious APK outside Google Play. 

Once installed, the malware first requests device administrator privileges, then works through a series of sensitive permissions, including access to Android’s Accessibility, which gives it much broader control over the device.

Once the permissions are granted, the malware retrieves its active command-and-control domain from a GitHub repository and caches the address. It then registers the infected device with the C2 server and sends information including a unique device ID, Android version, location, and mobile network operator. From there, the operators can use the malware’s C2 infrastructure to send instructions back to the phone.

Victim registration communication. Image: Zimperium

That control opens the door to the malware’s surveillance functions. Mantax Otax can collect SMS messages and notifications, steal contacts and call logs, track the device’s location, inspect browser history, and extract files and media. It can also abuse Accessibility to interact with messaging apps like WhatsApp and Telegram. 

Researchers also found that Mantax Otax abuses Android’s MediaProjection API to capture screenshots, record the screen, and stream its contents to the attackers. Separately, the malware can silently take photos using the device’s front or rear camera.

The malware can go further by showing a fake lock screen and capturing the user’s lock-screen PIN, giving attackers another way to access information and maintain control.

Older Android devices are especially vulnerable to its ransomware arm, allowing the malware to encrypt and delete original files, leaving the victim with .enc files and ransom notices.

A misconfiguration in the attackers’ Firebase server gave researchers a rare look at what happens after encryption. Mantax Otax forces an on-screen chat interface onto the victim’s device, creating a direct channel between the victim and the attackers for ransom negotiations. Zimperium found that Firebase backed the chat.

A newer version of the malware can torment victims with intrusive dialogs, touch prevention, disturbing overlays, and screen blocking — an apparent attempt to make them pay the ransom.

Attackers torment victims with a screen block.
Attackers torment victims with a screen block. Image: Zimperium

In effect, the malware gives its operators several ways to make the victim’s device difficult — and at times frightening — to use.

Recommendations for Android users

Zimperium says its mobile threat defense and application protection products detect the Mantax Otax samples it analyzed.

Prevention is especially important because granting the malware device administrator and Accessibility permissions can give attackers extensive control over the phone.

  • Avoid installing APKs from outside the Play Store.
  • Android Accessibility permissions can give an app extensive control over the device. Grant them only to trusted apps with a clear, legitimate need.
  • Keep Android and its security patches up to date, leave Google Play Protect enabled, and regularly review app permissions.

If you suspect an infection, disconnect the phone from the internet, do not enter passwords or banking details, and use another trusted device to change important passwords and enable two-factor authentication. Contact the device manufacturer, mobile carrier, or a qualified security professional for help securing or resetting the phone.

Read more: Another Android malware campaign combined social engineering, remote device control, and NFC technology to commit banking fraud within minutes.



Click Here For The Original Source.

——————————————————–

..........

.

.