{
  "id": 6732026,
  "title": "MantaxOtax fuses Android ransomware with surveillance tools",
  "url": "https://urgent.news/2026/09/11/mantaxotax-fuses-android-ransomware-with-surveillance-tools",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-11T07:25:03.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/mantaxotax-fuses-android-ransomware-with-surveillance-tools/"
  },
  "original_language": "en",
  "account": "A new Android malware dubbed MantaxOtax has been identified by security researchers, combining ransomware, spyware, and remote-control capabilities. This malicious software, analyzed by Zimperium's zLabs, was found to be linked to threat actors in Indonesia through language indicators and victim data. Initially distributed as standalone APKs on third-party file-sharing sites, the malware requires device administrator privileges and requests access to SMS messages, contacts, audio, images, and Android Accessibility services. Once installed, MantaxOtax can encrypt files using the Advanced Encryption Standard, with a separate key assigned to each victim. The ransomware targets Android 9 and earlier versions, avoiding certain system directories to minimize system instability. Post-encryption, original files are replaced with .enc copies, and a ransom message is displayed. The surveillance functions operate independently of storage access and can collect a range of data, including installed applications, hardware information, location data, browser histories, contacts, call logs, and SMS messages. The malware abuses Accessibility services to access WhatsApp and Telegram information, and uses Android's MediaProjection to take screenshots and record videos. Additionally, it can activate cameras and communicate directly with victims through on-screen chat interfaces. The malware's command-and-control infrastructure is designed to withstand disruption, with active server domains retrieved from a GitHub repository. Researchers also found a Firebase server misconfiguration exposing extortion conversations during their investigation.",
  "summary": "A newly documented Android malware strain called MantaxOtax combines ransomware, spyware and remote-control functions, enabling attackers to encrypt files, steal sensitive communications and obstruct victims from using infected phones. Mobile security researchers at Zimperium’s zLabs detailed the malware on September 9, saying analysed samples were linked through language indicators and recovered…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}