Android Malware Alert: Mantax Otax Steals OTPs & Chats
Android Malware Alert: Mantax Otax Steals OTPs & Chats

VIBE NEWS: India's Latest Breaking News

Your Daily Dose of What's Hot
Android Malware Alert: Mantax Otax Steals OTPs & Chats

Android Malware Alert: Mantax Otax Steals OTPs & Chats

IN SHORTA new Android malware named Mantax Otax steals OTPs, spies on WhatsApp chats, and harasses victims with disturbing pop-ups. Mobile security experts issue warning.

Urgent Mobile Security Threat Discovered

Android smartphone users are facing a serious new cybersecurity threat following the discovery of a sophisticated malware strain named Mantax Otax. Uncovered by researchers at mobile security firm Zimperium, the malicious software possesses a hybrid threat profile that integrates ransomware, spyware, and remote-control capabilities into a single package. Security experts warn that the malware poses extreme risks to financial data, private communications, and device integrity.

Unlike conventional phone viruses that focus on a single attack vector, Mantax Otax grants threat actors multi-layered access to hijacked devices. Mobile users are being urged to exercise heightened caution, as the malware is actively circulating outside official app stores through third-party platforms and targeted social-engineering tactics.

How the Malware Infiltrates Devices

Researchers found that Mantax Otax bypasses traditional app store security by spreading primarily as standalone Android package (APK) files. These malicious files are hosted on third-party file-sharing websites, messaging platforms, and phishing links spread via social-engineering schemes designed to trick victims into manually downloading and installing the app.

Once installed on a victim’s handset, the malware immediately requests high-level permissions, specifically Accessibility access and administrative privileges. If granted, these rights allow the malware to manipulate device settings, execute actions without user consent, and establish contact with attacker-controlled command servers. The virus registers the infected device by transmitting telemetry data, including the precise location, device build, and Android operating system version.

Extensive Spyware and Screen Hijacking Capabilities

The surveillance infrastructure built into Mantax Otax is particularly alarming for mobile users who rely on their devices for personal banking and sensitive messaging. The malware actively intercepts incoming SMS notifications to harvest one-time passwords (OTPs), while simultaneously extracting call logs, contact lists, web browsing history, installed application lists, precise GPS coordinates, and Google account details.

Furthermore, the malware aggressively targets popular instant messaging applications. By misusing Android’s Accessibility framework to impersonate the legitimate owner, Mantax Otax extracts private WhatsApp profile details and chat histories, alongside confidential Telegram conversations.

"Mantax Otax combines ransomware, spyware and remote-control capabilities, giving attackers several ways to take control of an infected phone."

To further compromise user privacy, the malware exploits Android’s MediaProjection feature. This functionality enables attackers to silently capture screenshots, record on-screen activity, and stream live phone usage back to remote servers. It can also remotely activate both the front and rear camera sensors to capture photographs without triggering visual indicators.

Psychological Harassment and Ransomware Tactics

In addition to intelligence gathering, security researchers identified that version two (v2) of Mantax Otax contains active psychological harassment components. The malware can unleash intrusive pop-up dialog boxes, play unexpected full-screen video files, display disruptive jumpscare images, and force the phone’s built-in speakers to broadcast text-to-speech audio messages at random intervals.

The threat also features a functional ransomware module. On older mobile operating systems—specifically devices running Android 9 or earlier—the malware scans accessible shared storage directories to encrypt personal photos, documents, and video files. While updated storage protections on Android 10 and newer versions effectively neuter the file-encryption mechanism, modern devices remain completely vulnerable to the malware’s extensive spyware features.

Targeted Regions and Defense Recommendations

Although telemetry data indicates primary active targeting against Indonesian mobile users, cybersecurity analysts emphasize that the threat is not geographically restricted. Any smartphone user who downloads unauthorized APK files from untrusted links remains susceptible to infection regardless of location.

To protect devices from compromise, security professionals advise users never to download application files from unknown websites or unsolicited message links. Additionally, users should carefully audit permission prompts and deny requests for Accessibility access or device administrator status from unfamiliar software. Zimperium confirmed that Google Play Protect successfully identifies and blocks Mantax Otax, making it essential for users to maintain active real-time scanning and keep operating systems updated.

TL;DR

  • Mobile security firm Zimperium discovered a dangerous new Android malware named Mantax Otax.
  • The malware spreads via malicious APK files hosted on third-party file-sharing sites and phishing links.
  • Mantax Otax steals OTPs, reads WhatsApp and Telegram messages, and records device screens.
  • It harasses victims using pop-ups, full-screen videos, sudden jumpscares, and text-to-speech audio.
  • Google Play Protect can detect the malware, so keeping it active helps safeguard devices.
#Android malware alert#Mantax Otax spyware#WhatsApp chat hacking#mobile safety tips#Zimperium security warning#OTP theft malware

Welcome

Sign In
Sign Up