ZeroHour
Story · 6 sources · 6 articlesfirst updated ()1

Google Play 'Early Access' Abuse and Mantax Otax Android Ransomware: Key Developments

mediumMalwareexploited in the wildimportance 50
What's new: New since the previous summary (2026-09-11T08:36:54Z): Cyber Security News (2026-09-11T12:14:12Z) adds Mantax Otax details — the malware deletes original files after AES encryption, abuses MediaProjection for screenshots and MP4 screen recordings uploaded to Catbox, captures the lock-screen PIN via a fake system-lock overlay, and can negotiate ransoms via an on-screen chat, while confirming…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Bitdefender found thousands of deceptive Google Play Early Access apps — which cannot receive public reviews or ratings — promoted with AI celebrity deepfake ads on TikTok and Facebook, including a GTA imitator that topped 1,000,000 downloads before…

Bitdefender research, reported on 2026-09-10 by SecurityWeek and The Hacker News and expanded on 2026-09-11 by CSO Online, documents widespread abuse of Google Play's Early Access program, in which published apps cannot receive public reviews or ratings — removing a key trust signal users normally rely on — allowing developers to push thousands of deceptive casino, reward, and utility apps. The apps are promoted through TikTok and Facebook ads using AI/deepfake celebrity videos promising cash rewards, PayPal payouts, crypto earnings, gift cards, and offers such as 250 free spins, but users receive only aggressive, endless advertising and the promised payouts never arrive; SecurityWeek notes no malware is delivered and some listings show thousands of installs, while CSO Online separately describes ad-fraud-capable utilities requesting excessive permissions. The Hacker News reports the GTA imitator 'Vice Streets: Open World' surpassed 1,000,000 downloads before disappearing from the Play Store. Named examples include the casino-style games 'Chicken Road' and 'Ice Fishing' and trademark abuse with apps named 'Grand Theft Auto V (Early Access)' that were later renamed; casino-style apps also sidestep gambling licensing, geofencing, and age-verification requirements. CSO Online adds that some Early Access apps requested unusual permissions — e.g., a QR scanner seeking to replace the device launcher — potentially enabling hidden web views that click ads, display fake login screens, or capture two-factor codes; Bitdefender recommends Android Enterprise Work Profiles and notes Google Workspace admins can disable Early Access apps for their organization. The Hacker News also notes its report coincides with disclosures on Android malware families Hagaseca, Mantax Otax, StreamRat, and GoldFactory's Gigabud banking trojan with its Vwork companion app used for cloned-app financial fraud. Separately, Zimperium researchers (GBHackers attributes the analysis to zLabs and Zimperium) describe Mantax Otax — sources use 'Mantax Otax' and 'Mantax OTAX' for the same family — Android malware combining ransomware, spyware, and harassment, distributed via malicious sideloaded APKs hosted outside Google Play on third-party file-sharing services through phishing, social engineering, and messaging lures; BleepingComputer reports it targets Indonesian users, while GBHackers and Cyber Security News link it to Indonesian threat actors. The malware abuses device-administrator and…

  • Bitdefender identified thousands of deceptive Google Play Early Access apps, which cannot receive public reviews or ratings, promoted via TikTok and Facebook ads using AI/deepfake celebrity videos (SecurityWeek and The Hacker News,…
  • Deepfake ads promised cash rewards, PayPal payouts, crypto earnings, gift cards, and 250 free spins; users received only aggressive advertising and the promised payouts never arrive (SecurityWeek, The Hacker News).
  • SecurityWeek reports no malware is delivered by the Early Access apps, though some listings show thousands of installs; CSO Online separately describes ad-fraud-capable utilities requesting excessive permissions.
  • The GTA imitator 'Vice Streets: Open World' surpassed 1,000,000 downloads before disappearing from the Play Store (The Hacker News).
  • Named examples include casino-style games 'Chicken Road' and 'Ice Fishing', and trademark abuse with apps named 'Grand Theft Auto V (Early Access)' later renamed (SecurityWeek).
  • Casino-style Early Access apps sidestep gambling licensing, geofencing, and age-verification requirements (The Hacker News).
  • A QR scanner app requested rights to replace the device launcher, which could enable hidden web views that click ads, display fake login screens, or capture two-factor codes; Bitdefender recommends Android Enterprise Work Profiles, and…
  • The Hacker News notes its report coincided with disclosures on the Hagaseca, StreamRat, and GoldFactory Gigabud banking trojan (with Vwork companion app for cloned-app financial fraud) Android malware families.

Coverage timeline

  1. · 5d ago
    SecurityWeek· 42
    Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

    Bitdefender reports deceptive Google Play Early Access apps use deepfake celebrity ads and fake rewards to lure users into ad-fraud schemes.

  2. · 5d ago
    The Hacker News· 50
    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Bitdefender found abuse of Google Play's review-free Early Access program to push thousands of deceptive casino and reward apps promoted with AI deepfake ads.

  3. · 5d ago
    BleepingComputer· 48
    New Android malware encrypts files, steals data, and harasses victims

    Zimperium details Mantax Otax, an Android malware combining ransomware, spyware, and harassment, spread via phishing APKs to Indonesian users.

  4. · 4d ago
    GBHackers· 46
    Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

    New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.

  5. · 4d ago
    CSO Online· 45
    Google’s Early Access is creating a blind spot for malicious apps

    Bitdefender found thousands of Google Play Early Access apps with deceptive behavior, including ad-fraud-capable utilities requesting excessive permissions on Android devices.

  6. · 4d ago
    Cyber Security News· 45
    New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

    Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.