A unique Android malware named Mantax Otax has been discovered by security researchers at Zimperium. This malicious software combines several harmful features, including the ability to steal information, provide remote access to attackers, act as a backdoor, and even encrypt files for ransom. It is being spread through APK files—Android app packages—found on third-party app stores, social media platforms, and phishing emails. The malware primarily targets users with Android versions 9 and older, as newer versions (10 and above) include built-in security features like Scoped Storage, which limit the malware's ability to access user data freely. Once installed, Mantax Otax can extract a wide range of personal information from the device. This includes browser history, contact lists, call logs, SMS messages, notifications, files, photos, and videos from the device's gallery. It can also retrieve Google account details, device specifications, location data, and a list of installed applications. Additionally, the malware can access WhatsApp messages and user profiles, and on Telegram, it can extract lock-screen PINs. It can also take screenshots, record the screen, livestream it to attackers, and use both the front and rear cameras to capture photos. After collecting the stolen data, the malware encrypts user files using the AES encryption method, deletes the original files, and adds a ".enc" extension to the encrypted files. Victims are then shown a chat interface where they must negotiate a ransom payment with the attackers to regain access to their files. This type of attack is commonly known as ransomware, where cybercriminals demand payment in exchange for decrypting the data. Researchers have noted that Mantax Otax is still under development, with two versions identified so far. The newer version includes changes in how it communicates over the internet, using WebSockets instead of traditional methods, and it also supports new commands from attackers. This indicates that the malware is evolving, becoming more sophisticated and harder to detect. Users are advised to keep their Android devices updated to the latest versions and to only download apps from trusted sources to reduce the risk of infection.