HomeRisk ManagementsMantaxOtax Android Malware Merges Ransomware and Spyware

MantaxOtax Android Malware Merges Ransomware and Spyware

Published on

spot_img

Emerging Threat: MantaxOtax Malware Raises Alarm with Ransomware and Surveillance Capabilities

The cybersecurity landscape has grown increasingly complex, with the emergence of new threats that exploit vulnerabilities in mobile devices. A prominent example is the MantaxOtax Android malware, which intertwines file encryption with sophisticated surveillance techniques. This malware not only robs users of their files but also allows attackers to siphon off messages, credentials, and sensitive device information while preventing access to infected phones.

In a detailed technical analysis published on September 9, Zimperium’s zLabs team connected this malware to Indonesian threat actors. Some samples of MantaxOtax were discovered distributed as standalone Android packages via a third-party file-sharing service, indicating a sideloading method for potential infection. This approach underscores a growing trend where malicious software is disseminated outside the confines of reputable app stores, putting unsuspecting users at risk.

The Ransomware Component

Upon installation, MantaxOtax proves itself to be an aggressive piece of malware by requesting device administrator privileges. It goes further by seeking access to a range of functionalities, including SMS, contacts, audio, and images. Crucially, it also requests access to Android Accessibility features, which empowers the malware with extensive control over the infected device’s operations.

One of the techniques used by MantaxOtax includes resolving its live command-and-control (C2) domain from a GitHub repository. Zimperium noted that this method enables operators to switch to new infrastructure seamlessly if a domain is blocked, allowing the malware to remain operational without needing significant code changes.

On devices running Android 9 or earlier, MantaxOtax executes a recursive scan of shared external storage. It encrypts user files using Advanced Encryption Standard (AES), then deletes the original files from the disk, replacing them with .enc copies. Each encryption key is fetched from the C2 based on the device’s Android ID, ensuring that each victim receives a unique key.

However, on devices running Android 10 and later, changes in Scoped Storage limit the scanning capability to the app’s own external files directory, significantly reducing the ransomware’s reach. Even so, Zimperium revealed that the malware employs tactics such as overwriting the victim’s personalized image files with ransom-related graphics, rendering the demand for payment undeniable.

An interactive chat interface is then opened on the infected device for negotiation purposes. Communication occurs through Firebase, although Zimperium has identified a misconfiguration that left some extortion dialogues exposed, perhaps compromising the attackers’ operational security.

A separate functionality in the malware simulates a system lock, thereby restricting user access while simultaneously capturing the lock screen PIN. This dual function emphasizes how MantaxOtax operates not just as ransomware but also as spyware.

Extensive Surveillance Capabilities

In addition to its ransomware capabilities, MantaxOtax exhibits extensive spyware functionalities. The malware collects a wide array of information, including app inventories, hardware specifications, user locations, browsing history, notification data, and contact lists. Additionally, it captures call logs and SMS messages, including sensitive one-time passwords (OTPs), as well as content stored in the device’s gallery.

Furthermore, it extracts personal data from messaging applications such as WhatsApp and Telegram, accessing profiles and chat histories through Accessibility features. Using the Android MediaProjection API, the malware can take screenshots, record the screen in MP4 format, and even stream nearly real-time data back to its operators. These recordings and images are hosted on a platform called Catbox, facilitating efficient retrieval for the attackers.

Zimperium indicated that clues in the malware’s code and recovered victim files suggest an Indonesian targeting strategy. This observation is bolstered by the discovery of a misconfigured server that inadvertently revealed what appeared to be the operators’ control panel, adding an intriguing layer to the investigation.

A subsequent version of MantaxOtax transitioned to using WebSocket communications, enhancing its capabilities with persistent screen locking and application blocking. It also introduced a transparent overlay that captures all touch inputs, rendering the device nearly unusable.

Other variants seem designed purely for psychological distress, employing a barrage of alert dialogues, incessant video overlays, image pop-ups occurring every 600 milliseconds, and even text-to-speech functionalities that audibly relay the attacker’s demands.

In summary, MantaxOtax stands as a foreboding example of how malware can evolve to incorporate both ransomware and spyware functionalities. Following closely behind another recently reported threat, THost9, which cloned banking apps into isolated profiles, MantaxOtax suggests a continuing trend of increasingly sophisticated attacks on mobile devices. Cybersecurity experts and users alike must remain vigilant against such emerging threats, ensuring their devices are secure and that they practice safe browsing habits.

Source link

Latest articles

White House Promotes Local First Strategy for Water Security

Texas Pilot Will Pave Way for National Expansion, Says Sean Cairncross By Shaun Waterman |...

Hackers Exploit Vulnerable LiteLLM AI Gateways for Root Access and Cloud Credential Theft

Security Concerns Emerge Surrounding LiteLLM AI Gateways Recent findings reveal alarming security vulnerabilities in LiteLLM...

Four Methods Organizations Generate Non-Human Insider Risk

As organizations increasingly integrate AI agents into their business operations, a new and complex...

Forged Identities Instead of Data Theft

Digital Identity, ...

More like this

White House Promotes Local First Strategy for Water Security

Texas Pilot Will Pave Way for National Expansion, Says Sean Cairncross By Shaun Waterman |...

Hackers Exploit Vulnerable LiteLLM AI Gateways for Root Access and Cloud Credential Theft

Security Concerns Emerge Surrounding LiteLLM AI Gateways Recent findings reveal alarming security vulnerabilities in LiteLLM...

Four Methods Organizations Generate Non-Human Insider Risk

As organizations increasingly integrate AI agents into their business operations, a new and complex...