New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Brief
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links.
Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s cameras, making one infection both an extortion and privacy crisis.
The campaign appears built around standalone Android app packages, or APKs, hosted on third-party file-sharing services.
Victims can be led to them through shared links, messaging apps or phishing messages, then persuaded to install the app outside the official store.
Its researchers linked the activity to Indonesian threat actors and found language clues and victim files suggesting an Indonesian focus. The discovery shows how mobile criminals are bringing surveillance, account theft and file encryption together in one package.
