ZeroHour
Story · 7 sources · 7 articlesfirst updated ()1

Google Play Early Access Abuse Surfaces Alongside Mantax Otax Ransomware and Gigabud Banking-App Cloning Campaigns

mediumMalwareexploited in the wildimportance 50
What's new: First consolidated coverage of this story (no prior merged summary): (1) Bitdefender disclosed abuse of Google Play's review-free Early Access program by thousands of deceptive apps, including 'Vice Streets: Open World' surpassing 1 million downloads (September 10-11, 2026). (2) Zimperium/zLabs disclosed the Mantax Otax ransomware-spyware family targeting Indonesian users, with attacker-victim…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Bitdefender found thousands of deceptive casino, reward, and utility apps abusing Google Play's review-free Early Access program, while Zimperium/zLabs detailed the Mantax Otax Android ransomware-spyware targeting Indonesian users and Group-IB tied…

A cluster of Android threat disclosures published September 10-11, 2026 covers app-store abuse, ransomware-spyware, and banking fraud. Bitdefender Labs reports threat actors are abusing Google Play's Early Access program, which blocks public reviews and ratings, to distribute thousands of deceptive casino, reward, and utility apps, many promoted on TikTok and Facebook with AI celebrity deepfake ads; a GTA imitator, 'Vice Streets: Open World,' surpassed 1 million downloads before disappearing from the Play Store. Casino-style apps sidestep gambling licensing, geofencing, and age-verification requirements, and one flagged utility, a QR scanner, requested device-launcher rights, enabling hidden web views that click ads and potentially display fake login screens or capture two-factor codes. Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization; its report coincides with disclosures on Android malware families Hagaseca, Mantax Otax, StreamRat, and GoldFactory's Gigabud banking trojan. Separately, Zimperium and zLabs detail Mantax Otax, a ransomware-spyware-harassment strain delivered via sideloaded APKs on third-party file-sharing services through phishing and social engineering, targeting Indonesian users and linked to Indonesian threat actors. It abuses Accessibility and device-administrator permissions to steal lock-screen PINs, SMS one-time codes, contacts (and location, per GBHackers), and WhatsApp/Telegram chats, captures screenshots and MP4 screen recordings via MediaProjection (uploads to Catbox), photographs victims via hidden camera previews, and AES-encrypts files with '.enc' extensions on Android 9 and older, with Android 10+ Scoped Storage limiting encryption reach but not surveillance. Ransom negotiation happens via an on-device Firebase chat, whose misconfiguration exposed attacker-victim conversations and victim data; the C2 at apimantax[.]otax[.]fun dynamically fetches its active domain from a GitHub repository, and a second version adds WebSocket communication, app blocking, jumpscare/full-screen overlays, and remote text-to-speech harassment. Google Play Protect already detects and blocks it on up-to-date devices via the App Defense Alliance. In parallel, Group-IB found that GoldFactory's Gigabud banking trojan, aimed at Indonesian Android banking customers, installs Vwork, a trojanized copy of the open-source Shelter app, to create a hidden Work Profile…

  • Bitdefender identified thousands of deceptive Google Play Early Access apps; the program blocks public reviews and ratings, removing a key trust signal.
  • GTA imitator 'Vice Streets: Open World' exceeded 1 million downloads before disappearing from the Play Store.
  • Early Access apps were promoted via TikTok and Facebook ads using AI celebrity deepfake videos; promised payouts never arrive, and casino-style apps sidestep gambling licensing, geofencing, and age-verification requirements.
  • A flagged QR scanner requested device-launcher rights, enabling hidden web views for ad-click fraud and potentially fake login screens or two-factor code capture.
  • Bitdefender recommends Android Enterprise Work Profiles; Google Workspace admins can disable Early Access apps for their organization.
  • Mantax Otax (Zimperium/zLabs) combines ransomware, spyware, and harassment, spread via sideloaded APKs on third-party file-sharing services through phishing lures, targeting Indonesian users and linked to Indonesian threat actors.
  • Mantax Otax AES-encrypts files and adds '.enc' extensions on Android 9 and older, deleting originals; Android 10+ Scoped Storage limits encryption reach but not surveillance.
  • It steals lock-screen PINs, SMS one-time codes, contacts (and location per GBHackers), and WhatsApp/Telegram chats via Accessibility abuse and a fake system-lock overlay; it captures screenshots and MP4 recordings via MediaProjection…

Coverage timeline

  1. · 7d ago
    The Hacker News· 50
    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Bitdefender found abuse of Google Play's review-free Early Access program to push thousands of deceptive casino and reward apps promoted with AI deepfake ads.

  2. · 6d ago
    BleepingComputer· 48
    New Android malware encrypts files, steals data, and harasses victims

    Zimperium details Mantax Otax, an Android malware combining ransomware, spyware, and harassment, spread via phishing APKs to Indonesian users.

  3. · 6d ago
    Dark Reading· 45
    Indonesia Hit by Android Banking App-Cloning Campaign

    GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.

  4. · 6d ago
    GBHackers· 46
    Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

    New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.

  5. · 6d ago
    CSO Online· 45
    Google’s Early Access is creating a blind spot for malicious apps

    Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.

  6. · 6d ago
    Cyber Security News· 45
    New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

    Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.

  7. · 6d ago
    Malwarebytes Labs· 45
    Android malware creates a hidden copy of your banking app

    Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.