Cookie Consent by Free Privacy Policy Generator

MantaxOtax Android Malware Combines Ransomware With Extensive Spyware Capabilities

Infosecurity Magazine reports that a new Android malware strain called MantaxOtax has been identified, combining ransomware functionality with extensive spyware capabilities. The malware encrypts files on infected devices while simultaneously exfiltrating sensitive data including contacts, messages, call logs, location information and credentials. Dark Reading adds that the malware is part of a broader campaign targeting users in Indonesia, where threat actors are exploiting Android Work Profile features to deliver the Gigabud Trojan and other malicious payloads. The campaign demonstrates how attackers are increasingly combining multiple attack techniques within a single malware family, maximising the potential impact and monetisation opportunities from each infection.

Why this matters for UK organisations

While this specific campaign is currently focused on Indonesia, the techniques and malware families involved are relevant to UK organisations, particularly those with mobile workforces, bring-your-own-device (BYOD) policies, or employees who travel internationally. Android malware that combines ransomware and spyware represents a dual threat: not only can it disrupt access to data and devices, but it can also exfiltrate sensitive corporate information, credentials and communications before the victim is even aware of the infection. For organisations with BYOD programmes or employees using personal devices to access corporate email, collaboration tools or cloud services, this type of malware can provide attackers with a pathway into corporate systems. The use of Android Work Profile features to deliver malware is particularly concerning because these features are designed to separate personal and work data on the same device, and users may not expect malicious activity within the work profile environment. Mobile devices are often less rigorously managed than laptops and desktops, and employees may install apps from untrusted sources, click on links in messages, or fail to apply security updates promptly. This creates opportunities for attackers to compromise devices and gain access to corporate data, credentials and communications.

What to review

UK businesses with mobile device management policies, BYOD programmes or employees accessing corporate data from personal Android devices should review whether their mobile security controls include malware detection, app vetting, and the ability to remotely wipe or isolate compromised devices. Consider whether your acceptable use policies clearly explain the risks of installing apps from untrusted sources, and ensure there is a clear process for employees to report suspicious behaviour on their devices. Review whether your mobile device management platform can enforce security policies on personal devices used for work, including requiring screen locks, encryption, and up-to-date operating systems. Consider whether your conditional access policies restrict access to corporate data based on device health and compliance status, and whether you have the ability to detect and respond to compromised devices before they can be used to access sensitive systems. Clarify who is responsible for managing mobile security, whether your security team has visibility into mobile device threats, and whether your incident response plans account for scenarios where employee devices may be compromised. If you allow BYOD, ensure that employees understand the security expectations, the risks of using personal devices for work, and the circumstances under which the organisation may need to remotely wipe or isolate a compromised device to protect corporate data.

Source: Infosecurity Magazine

News and blog posts
Infosecurity Magazine reports that a new Android malware strain called...
Today's brief highlights the importance of timely patching, clear ownership of...
Cloud security company Wiz has reported that attackers successfully chained two...
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two...