Android Ransomware Mantax Otax Encrypts Files and Streams Victim Screen in Real Time
Researchers at Zimperium have identified a new ransomware strain for Android named Mantax Otax that encrypts victim files while simultaneously recording and transmitting the device screen in real time.
The malware is distributed outside official app stores through standalone APK files hosted on file-sharing services. Links are delivered via messaging applications and phishing messages that trick users into manually installing the package.
Once active, Mantax Otax encrypts files using AES and appends the .enc extension. Ransom negotiations take place directly on the device through an on-screen chat interface displayed to the victim.
The malware records the screen as MP4 video and streams the footage to the operator while the device is in use. It also captures screenshots and uploads them to the Catbox service, and activates the camera to photograph the surrounding environment without any user notification.
Mantax Otax abuses accessibility services to read displayed content, intercepts SMS messages, and captures authentication codes sent by applications and banks. It collects contacts, call logs, and browsing history, steals credentials from WhatsApp and Telegram, and shows a fake lock screen to harvest the device PIN.
The impact depends on the Android version. On Android 9 and earlier the malware can reach all external storage. Starting with Android 10, Scoped Storage restrictions limit encryption reach, although surveillance functions continue to operate.
Language clues and files found on victims indicate a campaign aimed at Indonesia. Security recommendations include installing applications only from trusted stores, denying unnecessary accessibility, administrator, SMS, and camera permissions, and treating unsolicited APK files received via messaging with suspicion.
Related articles
Ukrainian Developer of LockerGoga, MegaCortex and Nefilim Ransomware Sentenced to 12 Years and Nine Months
A 52-year-old Ukrainian national has been sentenced by the Zurich District Court to 12 years and nine months in prison for his role as the lead developer of the LockerGoga, MegaCortex and Nefilim ransomware strains. The court determined that the malware he created was deployed against companies across dozens of countries, causing approximately 100 million Swiss francs in damages in the cases examined. Notable victims included train manufacturer Stadler Rail, which suffered the theft of around 500 GB of confidential data and a $6 million ransom demand in 2020, as well as climate equipment supplier Meier Tobler and banking software developer Crealogix. The defendant claimed he was performing ordinary cybersecurity consulting and was unaware of the intended use of his code, but investigators found ransom demand templates alongside the source code, undermining his defense. He has been in custody since October 2021 as part of a wider international investigation into attacks affecting more than 1,800 individuals and organizations in 71 countries. Upon release he will be banned from entering Switzerland for ten years, although the verdict remains subject to appeal.
IT Elements 2026 Conference: Ransomware Accounts for 69% of Incidents as Businesses Struggle with Backup Protection and AI Workloads
The fourth IT Elements conference opened in Moscow on September 9, focusing on business continuity after cyberattacks, infrastructure failures, and ransomware incidents. Jet CSIRT data showed that ransomware was responsible for 69% of confirmed incidents in the first half of 2026, with the majority occurring in the second quarter. Experts discussed the challenges of protecting backup copies from compromise, the frequent gap between stated RTO targets and real-world recovery times, and decision-making processes during major outages. The event also covered corporate AI agents, stressing the need for strong Data Governance, Data Quality, and DataOps practices to avoid unreliable model outputs. Research from Jet Infosystems and AC IKS revealed that over 30% of companies have already allocated dedicated network segments for AI workloads, with power demands reaching 80-200 kW per rack. On the networking track, testing of Eltex and EcoRouter devices showed adequate performance in standard scenarios but highlighted the lack of a universal domestic solution. The conference concluded with discussions on workforce changes, noting that AI is altering career paths for junior specialists and increasing demand for professionals who understand business context and can critically evaluate model results.
Ransomware Operators Linked to The Gentlemen Deploy TukTuk C2 Framework for Espionage and Credential Theft
Operators associated with the ransomware group The Gentlemen have adopted a new command-and-control framework called TukTuk to steal credentials, monitor compromised systems, and prepare environments for ransomware deployment. The framework was discovered on a server that also hosted tools for disabling EDR solutions, research on vulnerable drivers, and data apparently stolen from two large organizations. TukTuk includes agents for both Windows and Linux, along with its own backend and management panel that allows remote command execution, file transfers, screen capture, and device tracking through a single interface. One notable feature displays a fake Windows Security window on the victim's machine to capture entered credentials and send them directly to the attackers' panel. Researchers identified a DLL sideloading technique that abuses the legitimate Greenshot.exe executable to load a malicious log4net.dll library and launch the TukTuk agent. The server also contained EDRKiller, WarsawKiller, and UnknownKiller tools, plus materials on BYOVD attacks that leverage vulnerable legitimate drivers to gain kernel access and interfere with security products.
The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires
Ransomware has transformed dramatically since its origins in 1989, when evolutionary biologist Joseph Popp mailed AIDS-themed floppy disks demanding $189 via Panamanian mail. Early experiments like GPCode and Archiveus introduced stronger cryptography by the mid-2000s, while Reveton and CryptoLocker in 2012-2013 combined psychological pressure, Gameover Zeus botnets, and Bitcoin payments. Major incidents such as WannaCry, NotPetya, and attacks on Colonial Pipeline and JBS Foods demonstrated global reach and state-level involvement. Modern groups like REvil, LockBit, Maze, and Akira refined double extortion, Ransomware-as-a-Service models, access brokers, and virtualization targeting. Law enforcement operations have disrupted infrastructure repeatedly, yet the market fragments and regenerates with new brands. The core business model remains resilient due to easy initial access, layered extortion tactics, and victims' operational dependencies.