← Home
CYBERSECURITY

New Android Malware Combines Ransomware and Spyware to Target Users

September 18, 2026 Bill Toulas

How Mantax Otax Operates on Infected Devices

A newly discovered Android malware strain named Mantax Otax has emerged, blending ransomware and spyware functions to encrypt files, steal personal data, and harass victims through spam messages. First identified in September 2026, the threat originates from Indonesian cybercriminal groups distributing malicious APK files outside official app stores. Once installed, the malware locks user files and exfiltrates sensitive information while bombarding devices with unwanted notifications.

The malware gains access by tricking users into downloading fake applications that appear legitimate but contain hidden malicious code. After installation, it requests broad permissions that allow it to access storage, contacts, and messaging systems. It then uses AES encryption to lock files on the device, demanding payment for decryption keys. Simultaneously, it harvests login credentials, photos, and location data, sending them to remote servers controlled by attackers. Victims report persistent pop-up ads and spam SMS messages designed to pressure them into paying or clicking further malicious links.

What Makes This Threat Particularly Dangerous

Unlike typical ransomware that focuses solely on encryption, Mantax Otax integrates surveillance tactics to maximize harm and profit. By stealing data before encryption, attackers can threaten to leak information even if victims refuse to pay. The harassment component—through constant notifications and spam—aims to wear down user resistance. Security researchers note that the malware avoids Google Play Store detection by relying on third-party websites and phishing links shared via social media or messaging apps. Its Indonesian origin points to a growing trend of localized cybercrime groups adopting sophisticated, multi-functional tools.

Frequently Asked Questions

How can users protect themselves from Mantax Otax? Users should only install apps from trusted sources like the Google Play Store, avoid clicking suspicious links, and regularly update their device’s operating system. Installing reputable mobile security software can also help detect and block known threats.

Is paying the ransom recommended if infected? Security experts advise against paying ransoms, as it does not guarantee file recovery and encourages further criminal activity. Instead, victims should disconnect from the internet, seek professional help, and report the incident to authorities.

Read full article on Tech Site News →