Tendvane

← All articles

SecuritySeptember 11, 2026

This Android malware encrypts your files, then opens a chat window to negotiate

Most ransomware leaves a note and a payment address. Mantax Otax leaves a chat window.

Researchers at Zimperium's zLabs published their analysis on 9 September of an Android malware family they trace to Indonesian operators. It never comes from Google Play. It arrives as an APK on a file-sharing site, pushed by phishing messages and the usual social engineering, and it needs you to install it yourself. Once it is running it encrypts files with AES, leaving them with a .enc extension, locks the screen, and drops the victim into a live conversation with the person extorting them. Underneath that it is quietly taking the lock-screen PIN, SMS messages including one-time codes, contacts, call logs, browser history, photos, and WhatsApp and Telegram conversations, and it can capture screenshots and record video through the cameras.

The encryption half mostly fails on a current phone. Android 10 brought in Scoped Storage, which stops an app wandering through the whole of shared storage, so from Android 10 onwards the malware can only encrypt its own folder. On Android 9 and older it scans the lot. The spying half works regardless, and that is the part worth caring about, because an app reading your one-time codes is an app that can get into your bank while you are still trying to unlock your screen. Older handsets that stopped getting updates years ago sit in the worst position on both counts.

None of this touches you if you install apps from the Play Store and decline Accessibility permission to anything that has no business asking for it. Where it does reach your PC is the shape of the problem: files held hostage are only a crisis if they exist in one place. Tendvane's one-click backup copies Documents, Pictures and Desktop to a drive you choose, which turns a demand for money into an inconvenience.

Sources

Download Tendvane