Malware linked to Indonesian threat actors poses a significant risk of double extortion This article explores devices susceptible ransomware. . It steals sensitive data before encrypting files and demands payment through a chat feature.

Victims might be tricked into sideloading it via phishing messages, social-engineering lures, shared links, or messaging platforms. It retrieves its active C2 address from a GitHub repository, enabling operators to quickly change infrastructure if a domain is blocked. During device registration, Mantax OTAX provides an attacker with a unique device ID, geographic location, network operator details, and Android version. Pay to decrypt.” Android 10 and newer devices are less susceptible to its ransomware routine due to Scoped Storage, which limits malware access to user files.

But new Android protections don’t prevent surveillance, credential theft, or screen-locking features if dangerous permissions have been granted. The spyware is prolific. Mantax OTAX can steal browser history, contacts, call logs, SMS messages, notification content, installed apps, device information, Google account details, gallery media and location data.

It exploits Accessibility to target WhatsApp and Telegram data by simulating user interaction to collect chat content and account information. The malware can use Android’s MediaProjection API to take screenshots, record the screen and stream display content in near real-time. Indicators of Compromise Indicator Type Context / Description C2 Domain apimantax.otax.fun Observed The malware dynamically fetches a command-and-control domain.