
Every now and then, we come across reports of newly discovered malware making its rounds. In this case, a report from the security researchers at Zimperium discloses a new Android malware called Mantax Otax.
Newly-discovered Mantax Otax Android malware
So what makes this Mantax Otax Android malware particularly dangerous or scary? According to the researchers, it’s because it combines ransomware and spyware capabilities into one. Not only will it encrypt your files, it can steal sensitive data as well as spam and harass its victims.
How the malware works is after it’s been installed, it will request permission to use Accessibility service. This service is intended to help users with disabilities by giving them different ways to interact with apps. This includes reading on-screen content aloud, automated gestures, and more.
So by granting an app access to Accessibility services, it allows the malware to gain deeper control over your device.
Once the malware is in, it retrieves its C2 domain from GitHub and sends back details about its victim. This includes the victim’s location, carrier, Android version, and Android ID. It can even send commands through Firebase or WebSockets. Also, once it reaches your phone’s shared storage, it can encrypt files using victim-specific AES keys. It then replaces local images with ransom notices to let victims know they’ve been hacked and need to pay a ransom to decrypt their files.
The researchers also found it can extract messages from WhatsApp and Telegram, capture screenshots, record videos, and stream the victim’s screen.
Protecting yourself
As always, the usual precautions apply if you want to protect yourself from this malware. This includes keeping your phone up to date. According to the researchers, the ransomware and encryption capabilities of the malware only work reliably on Android 9 and older. So if you are using a much newer version of Android, you should be somewhat protected.
Also, since the attackers distribute the malware through malicious APKs hosted outside of Google Play, the most obvious thing you can do to protect yourself is to avoid sideloading these APKs. There are a few more trusted APK websites, like APKMirror and F-Droid if you must.
However, if someone sends you an APK file via email or instant messenger, you should probably skip it. Also, avoid websites that claim to host “cracked” or “modded” APKs. That being said, at the end of the day, the Google Play Store is still your safest bet.
The post Mantax Otax Malware Can Encrypt, Spy On, and Harass Android Users appeared first on Android Headlines.