Find notable cyber news and cases, enriched with sources, timelines, and signals.

MantaxOtax Android malware with ransomware and spyware control

Malware Activity
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The MantaxOtax Android malware now combines file encryption with spyware-style surveillance, putting infected phones at risk of both lockout and data theft. It can steal messages, credentials, and device data while also restricting access to the handset. The malware asks for device administrator rights, SMS access, and Android Accessibility, which expands control over the device. Its GitHub-resolved C2 and added screen locking and application blocking make containment and recovery more difficult.

Related Happenings

RatHat Android credential-theft malware

Malware Activity
H score27 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

About this happening: RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifi...

Latest development: 18.09.2026 09:17

Zimperium said RatHat pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the Android sandbox, unlock Developer Options, enable Wireless Debugging, and extract the 6-digit ADB pairing code. The malware stages native daemons that execute with shell-level privileges, lets a Go Agent masquerading as liblocal-service.so apply persistence and power management exemptions, and can re-install itself through the local service after uninstall. The operator also uses an FRP reverse-proxy client to establish a persistent reverse tunnel to the C2 server, while the malware can record finger presses on screen with a hardware-level keylogger.

RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers

Technical Analysis
H score28 First: 17.09.2026 16:00 Last: 17.09.2026 16:00 Sources 1

About this happening: RatHat is a new Android malware campaign analyzed by Zimperium zLabs and linked to China-based threat actors. It uses an AI-powered UI-automation subsystem to...

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

Manic Android malware activity with offline relay exfiltration

Malware Activity
H score29 First: 20.08.2026 13:02 Last: 20.08.2026 13:02 Sources 1

About this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

Timeline

  1. 09.09.2026 03:00 2 articles · 12d ago

    Zimperium links MantaxOtax to Indonesian threat actors and details Android ransomware-spyware behavior

    Initial Disclosure

    Zimperium's zLabs linked MantaxOtax to Indonesian threat actors and described an Android malware family that combines file encryption with spyware-style surveillance. The malware asked for device administrator privileges, SMS, contacts, audio, images and Android Accessibility, resolved its live C2 domain from a GitHub repository, encrypted user files with AES on Android 9 and earlier, and used Scoped Storage on Android 10 and later to narrow encryption on newer devices. It also overwrote victim image files with ransom graphics, opened extortion chats through Firebase, abused MediaProjection for screenshots and MP4 screen recording, and staged captures on Catbox while stealing messages, credentials, device data and account information from infected phones.

    Show sources