Google Play Early Access Abuse Surfaces Alongside Mantax Otax Ransomware and Gigabud Banking-App Cloning Campaigns
Bitdefender found thousands of deceptive casino, reward, and utility apps abusing Google Play's review-free Early Access program, while Zimperium/zLabs detailed the Mantax Otax Android ransomware-spyware targeting Indonesian users and Group-IB tied…
A cluster of Android threat disclosures published September 10-11, 2026 covers app-store abuse, ransomware-spyware, and banking fraud. Bitdefender Labs reports threat actors are abusing Google Play's Early Access program, which blocks public reviews and ratings, to distribute thousands of deceptive casino, reward, and utility apps, many promoted on TikTok and Facebook with AI celebrity deepfake ads; a GTA imitator, 'Vice Streets: Open World,' surpassed 1 million downloads before disappearing from the Play Store. Casino-style apps sidestep gambling licensing, geofencing, and age-verification requirements, and one flagged utility, a QR scanner, requested device-launcher rights, enabling hidden web views that click ads and potentially display fake login screens or capture two-factor codes. Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization; its report coincides with disclosures on Android malware families Hagaseca, Mantax Otax, StreamRat, and GoldFactory's Gigabud banking trojan. Separately, Zimperium and zLabs detail Mantax Otax, a ransomware-spyware-harassment strain delivered via sideloaded APKs on third-party file-sharing services through phishing and social engineering, targeting Indonesian users and linked to Indonesian threat actors. It abuses Accessibility and device-administrator permissions to steal lock-screen PINs, SMS one-time codes, contacts (and location, per GBHackers), and WhatsApp/Telegram chats, captures screenshots and MP4 screen recordings via MediaProjection (uploads to Catbox), photographs victims via hidden camera previews, and AES-encrypts files with '.enc' extensions on Android 9 and older, with Android 10+ Scoped Storage limiting encryption reach but not surveillance. Ransom negotiation happens via an on-device Firebase chat, whose misconfiguration exposed attacker-victim conversations and victim data; the C2 at apimantax[.]otax[.]fun dynamically fetches its active domain from a GitHub repository, and a second version adds WebSocket communication, app blocking, jumpscare/full-screen overlays, and remote text-to-speech harassment. Google Play Protect already detects and blocks it on up-to-date devices via the App Defense Alliance. In parallel, Group-IB found that GoldFactory's Gigabud banking trojan, aimed at Indonesian Android banking customers, installs Vwork, a trojanized copy of the open-source Shelter app, to create a hidden Work Profile…
- Bitdefender identified thousands of deceptive Google Play Early Access apps; the program blocks public reviews and ratings, removing a key trust signal.
- GTA imitator 'Vice Streets: Open World' exceeded 1 million downloads before disappearing from the Play Store.
- Early Access apps were promoted via TikTok and Facebook ads using AI celebrity deepfake videos; promised payouts never arrive, and casino-style apps sidestep gambling licensing, geofencing, and age-verification requirements.
- A flagged QR scanner requested device-launcher rights, enabling hidden web views for ad-click fraud and potentially fake login screens or two-factor code capture.
- Bitdefender recommends Android Enterprise Work Profiles; Google Workspace admins can disable Early Access apps for their organization.
- Mantax Otax (Zimperium/zLabs) combines ransomware, spyware, and harassment, spread via sideloaded APKs on third-party file-sharing services through phishing lures, targeting Indonesian users and linked to Indonesian threat actors.
- Mantax Otax AES-encrypts files and adds '.enc' extensions on Android 9 and older, deleting originals; Android 10+ Scoped Storage limits encryption reach but not surveillance.
- It steals lock-screen PINs, SMS one-time codes, contacts (and location per GBHackers), and WhatsApp/Telegram chats via Accessibility abuse and a fake system-lock overlay; it captures screenshots and MP4 recordings via MediaProjection…
Coverage timelineoldest first · each row is one article
- · 7d agoGoogle Play Early Access Abused to Push Thousands of Deceptive Android Apps
The Hacker News· 50
Bitdefender found abuse of Google Play's review-free Early Access program to push thousands of deceptive casino and reward apps promoted with AI deepfake ads.
- · 6d agoNew Android malware encrypts files, steals data, and harasses victims
BleepingComputer· 48
Zimperium details Mantax Otax, an Android malware combining ransomware, spyware, and harassment, spread via phishing APKs to Indonesian users.
- · 6d agoIndonesia Hit by Android Banking App-Cloning Campaign
Dark Reading· 45
GoldFactory exploits Android Work Profile to deliver the Gigabud banking trojan to Indonesian users via cloned banking apps, with Mantax and Otax spreading separately.
- · 6d agoMantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
GBHackers· 46
New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.
- · 6d agoGoogle’s Early Access is creating a blind spot for malicious apps
CSO Online· 45
Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.
- · 6d agoNew Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
Cyber Security News· 45
Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.
- · 6d agoAndroid malware creates a hidden copy of your banking app
Malwarebytes Labs· 45
Group-IB found the Gigabud Android banking trojan clones banking apps into a hidden work profile to conduct fraud undetected.