Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain.
Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion.
Unlike conventional Android ransomware that focuses primarily on locking or encrypting files, Mantax OTAX gives its operators broad visibility into a victim’s digital life before initiating the ransom phase.
The malware can steal lock-screen PINs, intercept SMS messages and one-time passwords, collect browser history, contacts, call logs, installed-app data, Google-account information and location details.
It can also access gallery files, capture images from the device’s cameras, and monitor messaging activity in WhatsApp and Telegram.
Analysed samples were distributed as standalone Android APKs hosted on third-party file-sharing services.
The distribution model relies on phishing, messaging lures and social-engineering tactics to convince targets to install an application outside the official Play Store ecosystem.
This sideloading approach bypasses much of the scrutiny associated with formal app-store publication and remains a recurring delivery mechanism for Android banking trojans and spyware.
After installation, Mantax OTAX requests device-administrator privileges, followed by permissions for SMS, contacts, audio and images.
It ultimately seeks Android Accessibility access, a high-risk permission that enables malware to observe and manipulate screen content, automate interaction with applications and harvest sensitive data displayed to the user.
The malware communicates with its command-and-control infrastructure over HTTPS and retrieves its active C2 domain from a GitHub repository.
This dynamic resolution mechanism allows the operators to change infrastructure if a domain is blocked without distributing a newly compiled APK.
The zLabs research team has discovered a Android malware, sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution.
Mantax OTAX Android Ransomware
Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published associated indicators in its public IOC repository.
Under the guise of this necessary administrative activity, the malware restricts user access to the device and intercepts the user’s lock screen PIN.

Mantax OTAX requests a unique encryption key from its C2 server using the victim device’s Android ID.
On Android 9 and older releases, it recursively searches shared external storage for documents, images, videos, archives, databases and cryptographic-key material.
The malware uses AES encryption, deletes original content and writes encrypted replacements with a .enc extension.
The ransomware deliberately avoids the Android/data and Android/obb directories, likely reducing the chance of destabilizing the device.
It then replaces selected local images with ransom-themed graphics containing the message: “Your files have been encrypted.
Pay to decrypt.” An on-device chat portal is subsequently displayed, enabling direct negotiations between the operators and victims through Firebase-backed communications.
Researchers said a Firebase misconfiguration exposed extortion conversations and other victim-related data.
Android 10 and later substantially reduce the ransomware module’s file-encryption reach through Scoped Storage.
However, that protection does not neutralize the malware’s surveillance, OTP theft, account takeover and device-disruption capabilities.
Mantax OTAX abuses Android’s MediaProjection API to capture screenshots, record MP4 video and stream screen content.
Screenshots are compressed and uploaded to the Catbox file-hosting service, while generated URLs are sent back to the operators. The malware can also silently take photographs with the front or rear camera.

A newer Mantax OTAX version uses WebSockets and introduces coercive controls including app blocking, transparent touch-blocking overlays, repeated dialog spam, full-screen video overlays, “jumpscare” image pop-ups and remote text-to-speech playback.
These features can obstruct recovery attempts while increasing psychological pressure on victims.
The campaign illustrates an important shift in mobile extortion: encryption is no longer the sole leverage point.
By pairing data theft, OTP interception, credential capture, continuous screen monitoring and device control with ransomware, operators can pursue double-extortion tactics even where modern Android storage protections limit file encryption.
Users should avoid APKs from untrusted links, keep Android and Play Protect updated, and treat unexpected Accessibility or device-administrator requests as a compromise warning.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Click Here For The Original Source.
