LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
ransomware

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]

zeroday.news ·

A new Android malware strain, dubbed Mantax Otax, has been identified as combining ransomware, spyware, and harassment capabilities. The malware, reportedly distributed by Indonesian operators, targets users through malicious APKs hosted outside of Google Play, employing phishing and social engineering tactics.

Upon installation, Mantax Otax requests extensive permissions via the Android Accessibility service. It then retrieves its command-and-control (C2) infrastructure domain from GitHub and transmits device details, including location, carrier, Android version, and device ID, back to the C2. Commands can be issued to infected devices via Firebase or WebSockets.

The ransomware component of Mantax Otax specifically targets Android devices running version 9 or older. This limitation is due to the Scoped Storage feature introduced in Android 10, which restricts an application's ability to encrypt files to its external-files directory. On vulnerable devices, the malware searches shared storage for specific file types, encrypts them using an AES key obtained from the C2 server, deletes the original files, and appends a ".enc" extension to the encrypted copies. It also replaces local images with ransom notes and initiates a full-screen, Firebase-hosted chat for ransom negotiation. Researchers were able to access attacker-victim communications due to a misconfiguration in the Firebase C2 server.

Beyond ransomware, Mantax Otax incorporates spyware and remote control functionalities. It can steal lock-screen PINs to maintain persistent access, read SMS messages and one-time passwords, and access call logs, contacts, browsing history, app lists, Google account information, and location data. The malware can also extract WhatsApp profiles and messages, as well as Telegram chats, through simulated interactions using Accessibility services.

Furthermore, Mantax Otax abuses Android's MediaProjection API to capture screenshots, record MP4 videos, and stream the victim's screen in near real-time via the Catbox file hosting service. It can also capture photographs using the device's cameras and upload them to the operator.

Version 2 of the malware introduced harassment features designed to pressure victims into paying the ransom. These include repeated dialog boxes, full-screen videos, rapid jumpscare image overlays, and remotely controlled text-to-speech messages played through the device speakers.

As a Google security partner through the App Defense Alliance (ADA), the company that identified Mantax Otax has ensured that the malware is detected and blocked by up-to-date Android devices with an active Play Protect service. Users are generally advised to avoid installing APKs from sources other than Google Play, to be cautious about granting Accessibility permissions to unfamiliar applications, and to only install apps from reputable publishers.

ransomwaremalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.