Smashing Security podcast #485: These researchers got drunk to hack an LG TV

MediumGraham Cluley · Graham Cluley·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
Android
Reported by
1 outlet

RESEARCHER

So we're gonna have a private conversation about our next crypto scam, and it would really be unfortunate if anyone had a recording of this.

ROBOT

Smashing Security, episode 485. These researchers got drunk to hack an LG TV with Graham Cluley and special guest Lianne Potter.

GRAHAM CLULEY

Hello, hello, and welcome to Smashing Security. Smashing Security, episode 485. My name's Graham Cluley.

LIANNE POTTER

And I'm Lianne Potter.

GRAHAM CLULEY

Lianne, welcome back to the show. Always great to have you here. Now, you are, of course, quite the aficionado when it comes to podcasts.

You've got podcasts coming out of your ears, haven't you?

LIANNE POTTER

I'm a millennial. You have to have multiple podcasts.

GRAHAM CLULEY

But you haven't just got one podcast, you've got multiple podcasts. So you've got your Compromising Positions podcast, all about cybersecurity. Excellent, groovy stuff there.

But you also do Tech Film Noir, where you are looking at old movies and seeing how well they've predicted future tech in particular, right?

LIANNE POTTER

It's just an excuse to watch the films I absolutely adore, mostly Arnold Schwarzenegger sci-fi movies.

GRAHAM CLULEY

Well, the latest episode you've put out is all about Weird Science, which was from about 1985, which hit me at precisely the right time. It was in my formative teenage years.

LIANNE POTTER

So does that explain it all then, Graham?

GRAHAM CLULEY

For anyone who hasn't seen it, it's about a couple of teenagers who decide to use technology to magic up the perfect woman in the shape of Kelly LeBrock.

LIANNE POTTER

And what a shape. That's all I have to say. Loving controversy on the podcast.

GRAHAM CLULEY

Goodness gracious me.

GRAHAM CLULEY

They were like, Lianne, you know, we can't really do this podcast 'cause it's not age-grade. And I said, well, that's the whole point of this podcast, that it's not age-grade.

The technology hasn't aged great and neither has the ethical quandaries.

GRAHAM CLULEY

Oh, well, I haven't seen it for a while, but I remember I enjoyed it at the time.

These couple of nerds, they boot up a Memotech MTX computer, a home computer, which wasn't very popular. And with it, they managed to create Kelly LeBrock.

Now, the thing I have to tell you, Lianne, is I had a Memotech MTX computer.

LIANNE POTTER

Boom! My head just exploded. No, you didn't. Really?

GRAHAM CLULEY

I really did.

LIANNE POTTER

We should have got you on the episode.

GRAHAM CLULEY

My original home computer was the Sinclair ZX81.

LIANNE POTTER

Yeah.

GRAHAM CLULEY

But my dad actually got us a Memotech MTX. I can't remember if it was the 500 or the 512. They had different amounts of RAM in them.

LIANNE POTTER

Yeah, yeah.

GRAHAM CLULEY

And I wrote games for them. I have to say, the graphics were nothing like as good as— That was my next question. How does it compare?

But it is a very nostalgic movie for me, 'cause it's like, oh my goodness, I remember this computer.

LIANNE POTTER

That's your life.

GRAHAM CLULEY

This was where I was at. It was fantastic.

LIANNE POTTER

Were you living the high life with 3 screens though, like this young lad does in the film?

GRAHAM CLULEY

Oh no.

LIANNE POTTER

'Cause I remember just thinking when I saw that, I was like, 3 screens, wow.

GRAHAM CLULEY

Who would need 3 screens? You've only got 2 eyes, haven't you?

LIANNE POTTER

I mean, it's—

GRAHAM CLULEY

2 feels like an extravagance to me.

LIANNE POTTER

Do you still have it or?

GRAHAM CLULEY

No, long gone, unfortunately.

LIANNE POTTER

Oh, such a shame, because we could do a follow-up episode and we could literally try and rebuild Kelly LeBrock from it.

GRAHAM CLULEY

I suspect that they go for a fortune on eBay now. They're probably very collectible.

LIANNE POTTER

I bet they are as well. Oh, that's so cool, Graham. That's really, really cool.

GRAHAM CLULEY

Anyway, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Intruder, and Vanta. We'll be hearing more about them later on in the podcast.

This week on Smashing Security. We won't be talking about how scammers tricked Revolut into handing over customer data by posing as a government agency.

You'll hear no discussion of how the Reddit account of HBO Max was hijacked by hackers to spread malware.

And we won't even mention how the UK and United States have joined forces to take down global scam centres. So, Lianne, what are you going to be talking about this week?

LIANNE POTTER

Well, I'm talking about a piece of Android malware that, if it was an all-you-can-eat buffet, it would get kicked out for being too greedy.

GRAHAM CLULEY

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

Plus, we've got a featured interview with Andy Hornegold of Intruder, so look forward to that. All this and much more coming up on this episode of Smashing Security.

This episode is sponsored by Intruder. Now, Joe, quick quiz. How often does your team ship code?

JOE

Multiple times a week. Maybe more if someone's had too much coffee.

GRAHAM CLULEY

And how often do you get a proper pen test?

LIANNE POTTER

Oof.

GRAHAM CLULEY

Once a year?

JOE

If we remember?

GRAHAM CLULEY

Well, that's the problem right there. Software moves weekly. Pen testing moves yearly. So most of what you ship never actually gets tested properly.

JOE

Which is exactly the gap Intruder's AI pen testing closes. You get the depth of a real manual pen test, but on demand whenever you need it.

No scoping calls, no 6-week wait, and it costs a fraction of the traditional price.

GRAHAM CLULEY

It's built by Intruder's own certified pen testers, so the agents catch the complex stuff human testers can miss, and every finding is validated against your actual app.

Real issues, not noise. You get an audit-ready report within hours.

JOE

And it plugs straight into Intruder's full platform — attack surface monitoring, cloud security, vulnerability management, all watching around the clock.

It flags what's exploitable, what to fix first, and how, so your team can act without waiting around for the security team.

GRAHAM CLULEY

Over 3,000 companies already trust Intruder with their attack surface.

JOE

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

GRAHAM CLULEY

Ooh!

GRAHAM CLULEY

So just head to intruder.io/smashing. That's intruder.io/smashing.

JOE

And thanks to Intruder for supporting the show.

GRAHAM CLULEY

Lianne, during your cybersecurity career, have you ever, or your staff, intentionally got a little bit sozzled? You know, something pickled, maybe legless, blotto, plastered.

Has that ever happened to you?

LIANNE POTTER

I can confirm nor deny that alcohol is sometimes involved in the cybersecurity industry, just to lubricate the onion tours going down nicely.

GRAHAM CLULEY

I think I might be a little bit of an oddity in the industry because I don't drink.

LIANNE POTTER

You're like some sort of lizard, you know, you just kind of take in nutrients from the ground and stuff.

GRAHAM CLULEY

Perhaps. Well, the reason I asked if alcohol has ever helped you in terms of cybersecurity is it turns out sometimes there is an acceptable reason to get a bit pissed.

LIANNE POTTER

I'm looking forward to hearing what this is.

GRAHAM CLULEY

Pissed in the British sense rather than the American sense of being upset. So, there's a bunch of researchers. They've just published their research into LG TVs.

Now, I don't know if you have one of those enormous TVs in your house, you know, the ones which cover about 90% of your wall.

LIANNE POTTER

I have been playing the LG game for quite a number of years as my TV of choice.

GRAHAM CLULEY

Okay.

LIANNE POTTER

So I'm very interested in what you have to say about this because I'm very scared.

GRAHAM CLULEY

Well, it seems to become the norm, doesn't it, to have a flashy smart TV leaving barely enough room for your sofa and your coffee table. And LG is one of the really major brands.

LIANNE POTTER

Yes.

GRAHAM CLULEY

Its TVs have been the subject of a deep dive investigation that's just been published on YouTube, because that's where you publish your cybersecurity research these days.

You don't do a paper at Black Hat, you produce a video.

LIANNE POTTER

Because TikTok dances are all so last year now.

GRAHAM CLULEY

So this is up on the Gamers Nexus YouTube channel, and they wanted to find out what these TVs get up to behind the scenes.

LIANNE POTTER

What do you mean? Did they go off and get drunk or something?

GRAHAM CLULEY

No, it's not the TVs getting drunk. I mean, they can barely get out the front door, let's face it, they're so enormous.

LIANNE POTTER

They can barely navigate to Spotify half the time.

GRAHAM CLULEY

Well, they found some pretty jaw-dropping things about these tellies because I'm afraid it can impact your privacy as well as earning the TV manufacturers an absolute ton of cash, and raises the question of who actually owns your TV.

So I asked about you and getting blotto, and the reason I ask that is this was key to how the team behind the investigation prepared for this research.

So setting up an LG TV — in fact, any TV probably these days — requires you to accept its terms and conditions, right?

There'd be some dialogue which pops up at some point and says, you can go and read 30,000 words of legalese.

LIANNE POTTER

Absolutely. Tons of pages.

GRAHAM CLULEY

Yeah.

LIANNE POTTER

That you're never gonna do.

GRAHAM CLULEY

You're never gonna do that. You just say, yeah, yeah, come on. I wanna see if the TV's any good.

LIANNE POTTER

Yeah.

GRAHAM CLULEY

So you click through. Now, we all know no one reads them, but of course you're kind of bound by those terms and conditions which you've agreed to.

And one of the terms and conditions may say something like, you agree not to test the TV for security vulnerabilities and find flaws.

LIANNE POTTER

Killjoys.

GRAHAM CLULEY

Yeah, killjoys. Exactly. You agree not to reverse engineer any of the algorithms.

But the investigators' lawyers apparently pointed out to the researchers, they said, look, you can't be legally bound by a contract which you agree to while drunk.

Because you don't actually—

LIANNE POTTER

Ah, okay. I like — does this loophole apply to life?

GRAHAM CLULEY

Sadly not. Sadly, I don't think, sorry, my lord, I was completely plastered. I don't think that'll get you off anything, particularly bad driving.

LIANNE POTTER

No.

GRAHAM CLULEY

So the researchers, they decided that they would use this loophole. So they got plastered. And they were quite clearly very merry at this point.

RESEARCHER

We have Ethernet plugged into Gamers Nexus LLC's TV. There you go. That Gamers Nexus purchased while it was inebriated heavily.

RESEARCHER

It was unable to agree to the EULA.

RESEARCHER

If a checkbox were checked.

RESEARCHER

It was entirely accidental.

RESEARCHER

Right.

RESEARCHER

Yes.

RESEARCHER

But we don't know if one had been checked.

RESEARCHER

Unlikely.

RESEARCHER

Because of the inebriation.

RESEARCHER

Yes.

RESEARCHER

Yeah. You see that Stanley Cup over there? It's just all margarita.

RESEARCHER

Just the entire thing.

Unknown

So.

GRAHAM CLULEY

They've sort of accepted the agreement, but LG can't actually hold them to any of it. And that's rather brilliant, I think.

So these agreements, they're so long, ploughing through them drunk isn't actually that different to doing it sober, I think. No one's gonna understand them.

So what did these researchers find? Well, it's bad news for anyone who owns an LG TV, Lianne.

LIANNE POTTER

Damn it.

GRAHAM CLULEY

Okay.

LIANNE POTTER

Hit me with it. Hit me with the bad news.

GRAHAM CLULEY

Because your TV might be listening even when it looks like it's been turned off.

LIANNE POTTER

Listening how? Like to what?

GRAHAM CLULEY

So of course, smart TVs these days have microphones just like your— are we allowed to use the Alexa word? Are we allowed to say Siri and Google?

LIANNE POTTER

You've just set everyone off now.

GRAHAM CLULEY

You've set everything off. But like all those smart devices, TVs these days have microphones.

So, you know, there is a way of commanding televisions through voice, and so they've got a microphone.

LIANNE POTTER

Yeah.

Unknown

Yeah.

LIANNE POTTER

There's a button that I press when I can't be bothered typing.

GRAHAM CLULEY

I suspect depending on your model of LG TV, it may be that you can give it a wake word as well, and you could actually just talk to it.

Unknown

I'm not sure.

GRAHAM CLULEY

It depends on the TV.

So in one test, these researchers staged a fake whispered conversation about a made-up crypto scam right in front of their TV, a TV that looked entirely switched off.

RESEARCHER

So we're gonna have a private conversation about our next rug pull crypto scam, and it would really be unfortunate if anyone had a recording of this.

All right, so the screen appears to be off right now. Currently, Wendell and I are in a boardroom to discuss our new crypto coin rug pull scam.

We don't want anyone to hear about this. We trust that no device in the thing is listening because of the appearance here.

And right, definitely things capturing video and audio surreptitiously would be very bad. Well, the only device in this room is the TV and it looks like it's off.

It sure does look like it's off. So the plan is we're gonna launch the coin, we're gonna let the price go up, then we're gonna sell all of our tokens and rug pull everyone.

RESEARCHER

Rug pull coins.

RESEARCHER

Yeah.

RESEARCHER

I mean, how else would you do a crypto?

RESEARCHER

I hope they don't hear about it.

GRAHAM CLULEY

The screen was black.

LIANNE POTTER

Mm-hmm.

GRAHAM CLULEY

There were no lights on. And afterwards they found that entire conversation. It saved it onto the actual TV.

Unknown

Word for word?

GRAHAM CLULEY

Word for word. It had been transcribed into the TV.

LIANNE POTTER

I mean, anyone with headphones on, Grim, how low was this whisper? Was it like this big?

GRAHAM CLULEY

It is extraordinary, isn't it? Some of these smart devices, they can hear you even when you whisper from the corner of a room, sometimes even when you're playing music.

LIANNE POTTER

I can barely hear other people when they whisper.

GRAHAM CLULEY

You need ears like an LG TV.

LIANNE POTTER

Exactly.

GRAHAM CLULEY

In another test, this TV picked up someone's voice clearly from around 70 feet away through a wall. Now, how big does your TV have to be for you to want to sit 70 feet away?

I can't imagine, so I can't understand the use case for that.

Now, to be fair, that particular demo and the fake crypto conversation one, they required the researchers to first exploit vulnerabilities.

To hack their way into the TV, which they were allowed to do because they were drunk when they went through the terms and conditions.

LIANNE POTTER

And we all know that hacking is so complicated nowadays.

LIANNE POTTER

And you know, you need lots of expertise to be able to do that. So it's totally unfeasible that this would happen.

GRAHAM CLULEY

Yes. Or you need an AI account maybe to look for the vulnerability as well.

So what they were proving was that this capability existed inside these televisions for a listening device to be built without your knowledge if someone with the right access, or should we call it the wrong access, wanted to do it.

So it had the capability to do that, even if you weren't pressing the button, even if you were 70 feet away, even if you weren't known.

So why do these TVs have the functionality to listen to you?

And it isn't, Lianne, so you can say, play the latest series of Game of Thrones or whatever it is that you wanted to watch.

LIANNE POTTER

Play the latest episode of Smashing Security.

GRAHAM CLULEY

Oh, such a crawler. Now, I'm sure you and lots of our listeners can guess what this is all about. It's about targeted advertising.

So modern smart TVs, they make a lot of their money, if not more of their money — if you actually look at their financial results — not from selling you the boxes, but from selling advertisers information about you and giving advertisers access to you as well.

LIANNE POTTER

So did they sit around in the marketing discussion and they were just like, do you know how people are always really paranoid that their smartphones are listening?

How about we take that to the next level and make it a dream come true?

GRAHAM CLULEY

Exactly. Let's have something else which people have around them a great proportion of the day.

And if the TV knows what you watch and it knows who else lives in your house and what other gadgets they own, that data has enormous value, of course.

And these TV manufacturing companies have entire divisions who are devoted to monetising the data in that way.

So the business model of a modern smart TV is built around watching you back.

LIANNE POTTER

Not literally though, right? Not like with cameras and stuff?

GRAHAM CLULEY

Well, not with most of them, no. And not in this particular test.

LIANNE POTTER

This is where you tell me it's got some sort of dolphin echolocation that when you're talking, it can see your shape.

GRAHAM CLULEY

Oh my goodness. That is a brilliant idea.

LIANNE POTTER

Oh no, you're watching TV with your hands down your pants like Al Bundy from Married... with Children again.

GRAHAM CLULEY

So, LG executives, they're shown in this video up on YouTube saying that LG owns the glass, meaning the screen that you paid £2,500 for, isn't really yours. It belongs to LG.

You are just borrowing it. Another big issue is that the TV knows about your whole home, not just you.

So the researchers discovered that these TVs are quietly scanning people's entire home networks, building a list of every device connected to the same Wi-Fi.

Yes, you may well gulp at the thought of that. So—

LIANNE POTTER

Yeah, I did. A lovely non-visual medium, but I was just like, ugh, okay.

GRAHAM CLULEY

So phones, your smartwatches, they even picked up a 3D printer — Lord knows what they're gonna do with that.

So this was regardless of whether those devices had anything to do with the TV at all, they were being picked up. And it was also picking up other nearby Wi-Fi signals.

So it was enough information potentially to work out roughly where in the world somebody physically was, which of course is useful in terms of sending out targeted advertising as well.

LIANNE POTTER

So I wasn't far off about echolocation then.

GRAHAM CLULEY

The good news is you don't have to worry about this because TVs have got privacy controls, right? Right, Lianne?

LIANNE POTTER

Right, right, right. We all know that companies love a good privacy control.

GRAHAM CLULEY

So on the LG TV, these researchers tested the button, which basically said, don't sell my personal information, don't be a bad guy.

Now that was turned off by default, and that was before the TV had even been connected to the internet.

So it wasn't possible to connect to the internet initially with that option turned off.

So when you retrospectively disabled the collection of that private data, that wasn't any good either, because when the researchers told the TV to delete their voice recordings, the recordings remained.

They only actually disappeared when the TV was completely unplugged from the wall — a complete and utter power-off, like pull the plug, not just the internet connection, not just the aerial or whatever you might have.

Pull the plug out of the wall, and then that information would be wiped.

LIANNE POTTER

This is where Martin Lewis, the money-saving expert, would be like, oh, I've been telling you for years to unplug your devices and save a bit of money.

GRAHAM CLULEY

Save yourself 13 pence.

LIANNE POTTER

Save yourself 13 pence, and then now save yourself from having all your data sold.

GRAHAM CLULEY

And ticking this box marked Delete My Data didn't actually delete your data. But it gets worse than that.

Again, this next bit comes from the same sort of hacked rooted TV, which they meddled with rather than one fresh out of the box.

They found with those modified units, even when they pulled out a network cable and physically pulled it out, so there was no internet connection at all — it wasn't connected via Wi-Fi, wasn't connected via an ethernet cable.

LIANNE POTTER

All the things you'd expect. Yeah.

GRAHAM CLULEY

The TV would carry on quietly recording and storing everything it picked up. And the moment you plugged the network back in, what do you think happened?

LIANNE POTTER

Was it party time at data and marketing HQ at LG?

GRAHAM CLULEY

Yeah, yeah, because all of that stored data got sent straight up to their servers again. So it'd been sort of waiting for the chance.

So unplugging your TV from the internet isn't really the safety net you might hope for.

The TV doesn't need to be online at the moment it's listening to you — it just needs to be online eventually.

LIANNE POTTER

Wow.

GRAHAM CLULEY

Now, to be fair to LG, they dispute a lot of this and the seriousness of a lot of this.

Their official line is that the TV only processes your voice when you deliberately press the button on your remote, like you were describing, or you say a wake word.

They say that any tracking features require you to opt in first, which sounds really reasonable.

But then you go and watch their marketing material of their advertising division, which is so boastful about all the data they're collecting when they're speaking to the big advertisers, like, we know everything about people.

LIANNE POTTER

I can imagine.

GRAHAM CLULEY

Yeah. So some people will think, well, you know, does this really matter that much?

But it does because you're not just sharing that data with advertisers, as we've talked about before.

Law enforcement agencies can quietly buy up this data and they can find out about your location, your behaviour.

LIANNE POTTER

Also, a lot of these organisations hiring contractors and stuff like that.

You know, that don't work for the company and you can't really — not casting aspersions on contractors — but you can't really control what they do.

And so if they take a shine to listening in onto certain conversations, what's gonna stop them?

GRAHAM CLULEY

And the fact that these TVs are vulnerable to security vulnerabilities, which have apparently been reported to LG now by these researchers who are able to do all kinds of hacks, means that potentially a criminal could break into a TV.

It's a TV which knows what you're watching, knows who's in the room, it knows roughly where your house is.

It makes you a more valuable target, I think, than someone who's just in the market for travel insurance or trainers or a different breakfast cereal.

LIANNE POTTER

Because how many times have you sat in your living room and phoned up your bank and your bank says, okay, give me your card details so that I can find your account.

Speaking to other providers and giving them account details and other things like that. Really private, personal conversations. Lots of lovey-dovey time on the sofa.

GRAHAM CLULEY

Imagine you're the CEO of an organisation and you're about to do a merger or an acquisition or a big announcement. A hacker could come in.

LIANNE POTTER

You just wanna watch an episode of Neighbours, calms you down just before a big presentation. Yeah, absolutely. It's gonna be terrible.

GRAHAM CLULEY

Imagine you're a politician.

LIANNE POTTER

Well, that's what I was thinking. I was thinking the scariest use case here would be espionage and very high-profile targets.

GRAHAM CLULEY

Yes, these sort of things do happen. It's not the first time we've talked about smart TVs being used for something other than watching TV.

LIANNE POTTER

Mm-hmm.

GRAHAM CLULEY

So it can be done for bad. Regular listeners will remember just a few episodes ago, we were talking about residential proxies.

Turns out these LG TVs are vulnerable to this kind of thing where other people's internet traffic can get quietly routed through your home connection without you realising, making your IP address look like the source of whatever they are up to.

And sure enough, these LG TVs are vulnerable to that. Nearly half of the apps they tested in LG's own app store had the ability to turn your TV into exactly that kind of proxy.

So on top of everything else, there's a decent chance your smart TV has been helping someone else disguise themselves on the internet.

So having depressed everybody, what can you do about this? And the advice from the researchers seemed straightforward. I was reading this and I thought, well—

LIANNE POTTER

I'm waiting with bated breath, obviously.

GRAHAM CLULEY

All right. So what their advice is is that you don't use the smart features of the TV itself. What you should do, they say, is why don't you use a separate streaming stick?

Amazon Fire Stick is the most famous one. If you want those smart features rather than using the apps which the TV manufacturers themselves have built into the operating system.

LIANNE POTTER

Okay. Yeah.

GRAHAM CLULEY

Now, the reason why I'm slightly nervous about that is of course, who's to say that Amazon can be entirely trusted as well?

LIANNE POTTER

Or any of them, yeah.

GRAHAM CLULEY

Maybe there's more eyes watching them as opposed to 5 Eyes watching them.

LIANNE POTTER

Which one is the lesser of the evils of all of them?

GRAHAM CLULEY

Yes, it's difficult, isn't it? So that was the advice which came out from the video is you may want to do that.

LIANNE POTTER

I think my mum had better advice, to be honest, because what she used to always tell me is, don't watch too much TV, it'll rot your brain.

But really, don't watch too much TV because it'll steal your identity.

JOE

This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.

GRAHAM CLULEY

Ransomware that thinks for itself, worms that rewrite their own playbook mid-attack, agents happily chaining exploits together without ever pausing to ask a human, is this all right?

JOE

Which is all very interesting, just so long as it isn't your network they're experimenting on.

GRAHAM CLULEY

And that's the problem.

When a machine can scope out your network, break in, and start creeping sideways through it faster than you can finish your coffee, you can't rely on the hope that someone will notice the alert eventually.

And this is where ThreatLocker earns its keep. Default deny and least privilege sit right in the agent's path, so nothing runs just because it asks nicely.

Application allowlisting decides what's even allowed to execute. Ring-fencing keeps trusted apps from wandering off and touching things they shouldn't.

And privileged access management quietly confiscates the elevated access nobody needed in the first place.

JOE

The attacker may be moving faster, but the controls are already in place.

Agentic AI doesn't make established security principles obsolete; it makes getting them right considerably more urgent.

GRAHAM CLULEY

So while the attacks are picking up speed, make sure ThreatLocker is already standing in the way. Head to threatlocker.com/smashing to find out more and grab your free demo.

JOE

That's threatlocker.com/smashing, and thanks to ThreatLocker for supporting the show.

GRAHAM CLULEY

Lianne, what's your story for us this week?

LIANNE POTTER

So, you know how all the frontier AI companies are now saying, let's slow down on superintelligence?

I think we in cyber need to get together and have a really hard, long look at our malware naming conventions.

GRAHAM CLULEY

Okay.

LIANNE POTTER

So today I'm going to talk about MantaXotax.

GRAHAM CLULEY

I beg your pardon?

LIANNE POTTER

MantaXotax.

GRAHAM CLULEY

Is that all one word?

LIANNE POTTER

No, it's 2 words.

GRAHAM CLULEY

Okay.

LIANNE POTTER

I think I'm saying it correctly.

But it made me think about whoever named this strain of malware was just looking around the room and saw a man and maybe their tax return and was just like, that's the name of this strain of malware.

So I Googled it because I thought, does this mean something really special or clever? And it is an Indonesian piece of malware. And in Indonesian, Mantax means awesome.

GRAHAM CLULEY

Oh, okay.

LIANNE POTTER

Which got me thinking and actually got my goat, because remember last time I was on, I was talking about the phishing service as a platform called Greatness.

And honestly, who is naming this stuff? Cybercrime brought to you by the makers of Live Laugh Hack signs.

Sorry, I'm digressing here, but cyber naming conventions is just such a touchy subject for me.

Awesome for a malware, Greatness for a phishing as a service platform — our naming conventions suck. It's an embarrassment. That's not the story though.

I just needed to get that off my chest.

LIANNE POTTER

So a few days ago, it was disclosed that MantaXotax is a horrible little bit of Android malware that is doing the rounds.

But there's something a little bit special about this one, because malware tends to specialise.

So you've got malware that does info stealing, you've got your RATs, you've got your spyware, you've got your ransomware, but MantaXotax — I'm just going to call it Mantax going forward — apparently looked at all those and went, why should I choose between those?

Why don't I just use all of them?

So this piece of Android malware can nick your texts, your contacts, your browser history, your WhatsApp and Telegram data, grab screenshots, record your screen, take photos using your camera.

And just when you're thinking, well, that's quite bad, it then encrypts your files and demands a ransom.

GRAHAM CLULEY

Quite bad? I'd say this is worse than having an LG TV.

LIANNE POTTER

On the scale of things, perhaps. It gets worse.

GRAHAM CLULEY

Okay.

LIANNE POTTER

So the cybersecurity experts are calling this a new Android malware cybercriminal cocktail, partly because it mixes ransomware and malware into a lovely fusion-style drink, but also because once it hits you, your phone ends up shaken, stirred, and absolutely on the rocks.

GRAHAM CLULEY

My goodness.

LIANNE POTTER

And it's interesting because it's spread through dodgy APKs, through Telegram channels, forums, and phishing rather than the official Google Play App Store.

GRAHAM CLULEY

Oh, okay. So if you sideload an app onto your Android phone, rather than going from the Google Play Store, you could potentially install this piece of malware.

LIANNE POTTER

Correct. And apparently it's really nasty on old versions of Android too. So as I say, it's an Indonesian flavour of malware.

And how it works is, you don't go through the Google Play Store — you're likely to get this sent to you by phishing or through socially engineered messages.

Again, through WhatsApp and Telegram.

And once you install it, the malware asks for permissions to use your accessibility services, and then once it's got that, it pretty much has control of everything it needs to compromise your device.

And then in typical malware style, it pings to a command and control infrastructure, sends the data of the victim back to its location, and then it starts going rogue.

It starts everything that's in a cybersecurity textbook.

You know, as I say, remote control, locks your screen, collects all your passwords, especially one-time passwords if you get SMS messages through there, everything.

But what is a bridge too far in this case is it's also got something called harassment features.

So if your day wasn't rude enough about your phone getting locked and full of malware and ransomware, they actually added in — and this is an actual line of code, it's literally called this — jump scare.

GRAHAM CLULEY

Jump?

LIANNE POTTER

Not like in horror movies, jump scare. So they know exactly what they're doing — it's literally a line of code called jump scare.

And for an extra bit of spice in your awful day of getting your phone owned, they send you rapid full-screen videos and images, and they even use text-to-speech messages played through the device's speakers, screaming at you, shouting at you.

So this isn't just your typical malware strain. For me, it's a reminder that the Android ecosystem is a bit like the devil's playground, really.

I mean, if you're going to sideload random apps from places like Telegram, then you're basically the cybersecurity equivalent of getting a drink from someone called Kevlar Dave in a nightclub that you've never met before.

So the piece of advice to avoid this is to make sure you have an updated operating system, because as I say, the old ones are hit hardest, which is just true to life, I think.

Basically, don't install random crap from Telegram.

GRAHAM CLULEY

Yeah. So this jump scare, which it displays — I imagine that isn't something which happens while it's stealing your data. That's after they've encrypted you.

This is an extra inducement to pay the ransom, I imagine. It's like, my phone has gone completely haywire.

LIANNE POTTER

It would scare the crap out of me. Yes. It happens afterwards.

Originally published by Graham Cluley. © Graham Cluley. Written by Graham Cluley.

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. Graham Cluley ↗Established SourceFirst reported

    2026-09-16 23:07 UTC

Related stories

Smashing Security podcast #485: These researchers got drunk to hack an LG TV | CyberBrief