Mantax Otax: The Android Malware That Encrypts, Spies, And Harasses
Security researchers have identified a new and dangerous strain of Android malware called Mantax Otax. The malware merges ransomware and spyware capabilities into a single, highly aggressive attack tool. Indonesian threat actors reportedly operate the campaign, targeting victims with encryption, data theft, and psychological harassment. Mobile security company Zimperium first documented the threat and published detailed technical findings about its behavior.

According to Zimperium's zLabs research team, Mantax Otax represents a dangerous tactical evolution in mobile threats. The malware seamlessly integrates comprehensive spyware capabilities with traditional ransomware behavior into a single attack vector. It compromises user privacy through an intrusive set of surveillance features while simultaneously extorting victims for payment. Researchers describe the combination as a "high-impact double-extortion threat" that pressures victims on two fronts at once.
Operators distribute Mantax Otax as a standalone Android APK via third-party file-sharing platforms rather than through Google Play. Attackers persuade victims to manually download and install the application through shared links and messaging platforms. Phishing messages and social engineering campaigns commonly drive traffic toward these malicious download pages. This sideloading approach lets the operators bypass the security controls built into official app stores entirely.
Once installed, the malware immediately requests device administrator privileges to secure a strong foothold on the phone. It then solicits an extensive list of sensitive permissions, covering SMS messages, contacts, audio, and stored images. The final step in this escalation process involves requesting Accessibility service permissions from the unsuspecting user. Granting this permission hands the attacker near-total control over the device's core functionality and interface.
Mantax Otax communicates with its command-and-control server over HTTPS to keep its traffic encrypted and harder to inspect. The malware retrieves its active C2 domain dynamically from a GitHub repository rather than hardcoding it. This technique lets operators quickly pivot to new infrastructure whenever a domain gets blocked or taken down. No code changes are required on infected devices when the malware switches to fresh server addresses.
After resolving its C2 server, the malware generates a unique device identifier and automatically registers the victim. This registration request exfiltrates telemetry, including geographic location, mobile network operator, and installed Android version. Once registration succeeds, the malware establishes a persistent control loop and executes tasks issued through Firebase infrastructure. Zimperium researchers noted that later versions shifted this communication to WebSockets for real-time command delivery.
Ransomware Capabilities Target Older Devices
Mantax Otax's file encryption routine only functions effectively on devices running Android 9 or earlier. The malware requests a unique AES encryption key from its C2 server, tied to the specific victim's Android ID. It then scans shared external storage for media files, documents, archives, databases, and cryptographic key files. After encrypting each target file, the malware deletes the original and appends a ".enc" extension.
To maximize psychological pressure, the malware replaces local image files with ransom notices reading, "Your files have been encrypted. Pay to decrypt." It then forces a full-screen chat interface to open, compelling victims to negotiate payment directly with the attackers. Zimperium researchers discovered a misconfiguration in the Firebase backend that exposed these extortion conversations to outside observers. That exposure allowed the research team to review real negotiations between operators and their victims firsthand.
Newer Android versions largely blunt this ransomware component thanks to built-in operating system protections. Android 10 and later devices enforce Scoped Storage, which restricts apps to their own isolated external files directory. This sandboxing dramatically limits which files the malware can actually reach and encrypt on modern hardware. As a result, the ransomware module poses a serious threat, mainly to outdated Android devices.
Beyond encryption, Mantax Otax functions as a full-featured spyware platform capable of harvesting enormous amounts of personal data. The malware intercepts SMS messages and one-time passwords, effectively defeating many forms of two-factor authentication. It also collects call logs, contact lists, browsing history, installed application inventories, and Google account details. Real-time location tracking rounds out its extensive data-harvesting engine, targeting compromised Android devices.
The malware specifically targets popular messaging platforms to breach otherwise private conversations between victims and their contacts. Using Accessibility services, it simulates user taps to open WhatsApp and extract profile information and message content. It performs similar automated actions against Telegram, harvesting chat histories and account credentials from the compromised application. This messaging-focused targeting gives operators direct insight into a victim's most sensitive communications.
Mantax Otax also abuses Android's MediaProjection API to conduct continuous, near-real-time surveillance of the victim's activity. Its capabilities include:
- Capturing static screenshots and compressing them into JPEG format for exfiltration
- Recording full-motion screen video in MP4 format for later review
- Streaming live display frames back to attackers using Base64 encoding
- Silently photographing victims through either the front or rear device camera
Captured screenshots, videos, and photos get uploaded to the Catbox file-hosting service, with download links relayed back to the operator's control panel. This gives attackers passive visibility into financial transactions, private messages, and any other sensitive content displayed on the victim's screen.
Zimperium identified two distinct versions of Mantax Otax, with the second representing a significant escalation over the first. Version 2 introduced device-locking features, including a "touchBlock" command that creates an invisible overlay blocking all touch input. It also added a "blockapp" command that remotely restricts access to any application installed on the compromised device. These features give operators near-total control over whether a victim can use their phone at all.
The newest version also introduces deliberate harassment routines designed purely to intimidate and pressure victims into paying. One researcher explained that these additions "add an intimidation component to the attacks," reinforcing the ransom demand psychologically. Notable harassment features documented by Zimperium include:
- Automated dialog spamming that floods the screen with intrusive alert boxes
- Full-screen video overlays that obstruct the victim's view of the device
- Rapid "jumpscare" image overlays that flash every 600 milliseconds for a disorienting effect
- Remote text-to-speech commands that play threatening audio messages through device speakers
These intimidation tactics work alongside the ransomware and spyware modules to maximize pressure on victims. Attackers can combine screen blocking, application restrictions, and audio harassment simultaneously to make the device nearly unusable. Zimperium participates in Google's App Defense Alliance, meaning its threat intelligence already feeds directly into Android's built-in protections. Devices running an up-to-date, active Google Play Protect service should automatically detect and block Mantax Otax.
However, users running outdated Android versions or those who disable Play Protect remain considerably more exposed to infection.
Security experts continue to recommend several basic precautions to avoid mobile malware such as Mantax Otax. Users should avoid installing APK files from outside Google Play, particularly those shared via messaging apps. They should also scrutinize any application requesting Accessibility permissions, since legitimate apps rarely need this level of device control. Sticking to reputable, well-known publishers further reduces the likelihood of encountering hybrid ransomware and spyware threats.
Keeping Android devices updated to the latest available version also meaningfully limits the malware's ransomware capabilities. Scoped Storage protections built into Android 10 and later already blunt much of the file-encryption threat. When combined with cautious app installation habits, these measures substantially reduce the risk Mantax Otax poses to everyday Android users.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion