Mantax Otax Android malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment. It spreads through malicious APKs outside Google Play and uses phishing and social engineering to push installation, then requests Accessibility permission for deep device control. The malware pulls its C2 from GitHub, can issue commands through Firebase or WebSockets, and is already detected and blocked on up-to-date devices with active Play Protect.
Related Happenings
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware Activity
H score19
First: 10.09.2026 17:36
Last: 10.09.2026 17:36
Sources 1
About this happening:
The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
Hagaseca Android RAT spread via THost9 loader and ADB worm behavior
Malware ActivityAbout this happening: The Hagaseca Android remote access trojan is being spread through the THost9 loader and a worm component that scans exposed ADB services, enabling persistent device co...
MantaxOtax Android malware with ransomware and spyware control
Malware Activity
H score32
First: 10.09.2026 16:00
Last: 10.09.2026 16:00
Sources 1
About this happening:
The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can ste...
MantaxOtax Android malware with ransomware and spyware control
Malware ActivityAbout this happening: The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can ste...
StreamRat Android banking trojan with remote-control capabilities
Malware Activity
H score42
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
About this happening:
StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
StreamRat Android banking trojan with remote-control capabilities
Malware ActivityAbout this happening: StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
Timeline
-
11.09.2026 00:40 2 articles · 2h ago
Mantax Otax Android malware combines ransomware, spyware, and harassment
Initial DisclosureMantax Otax is a new Android malware strain distributed by Indonesian operators through malicious APKs outside Google Play and phishing or social engineering messages against victims. After installation, it requests Accessibility permission, retrieves a C2 domain from GitHub, can receive commands through Firebase or WebSockets, encrypts files on Android 9 or older with a victim-specific AES key, appends the .enc extension, and steals data such as SMS, one-time passwords, contacts, browsing history, Google account information, screenshots, videos, and camera photos while also using full-screen notices and dialog overlays to harass victims.
Show sources
- New Android malware encrypts files, steals data, and harasses victims — www.bleepingcomputer.com — 11.09.2026 00:40
- New Android malware encrypts files, steals data, and harasses victims — www.bleepingcomputer.com — 11.09.2026 00:40