Mantax Otax: New Indonesian Mobile Ransomware with Spyware Capabilities
Article Content
The zLabs research team has identified a new mobile malware strain named Mantax Otax, linked to Indonesian threat actors. This malware combines ransomware and spyware functionalities, compromising user privacy by recording screens, extracting browser history, and stealing sensitive information. It targets older Android versions by encrypting data and demanding ransom through an interactive chat interface post-infection. The malware is distributed as a standalone APK via third-party file-sharing services, utilizing social engineering tactics to encourage installation. Upon installation, it requests extensive permissions, including device administrator rights, to gain control over the device. Communication with its Command and Control (C2) server is secured via HTTPS, and it employs a dynamic domain resolution mechanism to maintain operational resilience. The malware's sophisticated nature poses a significant threat to users, particularly those using outdated Android systems.
Key Points: • Mantax Otax integrates ransomware and spyware, targeting older Android devices. • The malware is distributed via third-party APKs, leveraging social engineering tactics. • It employs a dynamic C2 resolution mechanism to evade detection and maintain control.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.