MantaxOtax Android malware with ransomware and spyware control
Malware Activity
Summary
Hide ▲
Show ▼
The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can steal messages, credentials, and device data while also restricting access to the handset. The malware asks for device administrator rights, SMS access, and Android Accessibility, which expands control over the device. Its GitHub-resolved C2 and added screen locking and application blocking make containment and recovery more difficult.
Related Happenings
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android bank-fraud malware rental service
Malware Activity
H score21
First: 07.07.2026 20:10
Last: 07.07.2026 20:10
Sources 1
About this happening:
The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
RedWing Android bank-fraud malware rental service
Malware ActivityAbout this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
Rokarolla Android banking trojan activity
Malware Activity
H score26
First: 16.06.2026 16:15
Last: 16.06.2026 16:15
Sources 1
About this happening:
The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Rokarolla Android banking trojan activity
Malware ActivityAbout this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...
Timeline
-
09.09.2026 03:00 2 articles · 1d ago
Zimperium links MantaxOtax to Indonesian threat actors and details Android ransomware-spyware behavior
Initial DisclosureZimperium's zLabs linked MantaxOtax to Indonesian threat actors and described an Android malware family that combines file encryption with spyware-style surveillance. The malware asked for device administrator privileges, SMS, contacts, audio, images and Android Accessibility, resolved its live C2 domain from a GitHub repository, encrypted user files with AES on Android 9 and earlier, and used Scoped Storage on Android 10 and later to narrow encryption on newer devices. It also overwrote victim image files with ransom graphics, opened extortion chats through Firebase, abused MediaProjection for screenshots and MP4 screen recording, and staged captures on Catbox while stealing messages, credentials, device data and account information from infected phones.
Show sources
- MantaxOtax Android Malware Combines Ransomware With Spyware — www.infosecurity-magazine.com — 10.09.2026 16:00
- MantaxOtax Android Malware Combines Ransomware With Spyware — www.infosecurity-magazine.com — 10.09.2026 16:00