Cybersecurity and Privacy

New Android Malware Mantax Otax Combines Ransomware, Advanced Spyware, and Psychological Harassment Tactics

Cybersecurity researchers have uncovered a sophisticated and aggressive new strain of Android malware known as Mantax Otax, which merges traditional ransomware capabilities with invasive spyware and psychological harassment modules. Discovered and analyzed by mobile security firm Zimperium, the malware is currently being distributed primarily by Indonesia-based threat actors. By leveraging malicious Android Package Kits (APKs) hosted outside official distribution channels, the operators are successfully targeting vulnerable mobile users through targeted social engineering and phishing campaigns.

The emergence of Mantax Otax highlights a concerning evolution in mobile cybercrime. While mobile ransomware has historically relied on locking device screens or encrypting a limited set of files, this new threat actor methodology combines financial extortion through data encryption with extensive corporate-grade espionage and direct harassment techniques. Security analysts warn that this multi-pronged approach significantly raises the stakes for victims, increasing the likelihood of compliance under extreme psychological pressure.

Infection Vector and Initial Access

The lifecycle of a Mantax Otax infection typically begins outside the safety of the Google Play Store. Operators rely on social engineering vectors, enticing potential victims via messaging applications, SMS phishing (smishing), and deceptive web links to download rogue APK files. Once the user executes the file and installs the application, the malware initiates its malicious routine by immediately requesting permission to abuse Android’s Accessibility service.

New Android malware encrypts files, steals data, and harasses victims

Granting Accessibility permissions provides the malware with near-total control over the compromised device. This mechanism bypasses standard user interfaces, allowing the application to silently grant itself additional privileges, simulate user touches, and interact with the operating system on behalf of the attacker.

Following successful installation, Mantax Otax establishes communication with its command-and-control (C2) infrastructure. To maintain operational resilience, the malware dynamically retrieves its primary C2 domain hosted on GitHub. Once connected, it transmits a comprehensive telemetry profile of the infected smartphone to the operators. This telemetry includes precise geographical location data, cellular carrier information, the specific Android OS version, and a unique device identifier. To issue subsequent instructions, the threat actors leverage Firebase and WebSockets, enabling real-time remote execution of commands.

Targeted Ransomware Mechanics and Operating System Limitations

The ransomware component of Mantax Otax is specifically engineered to cause maximum disruption by targeting user files, though its effectiveness is heavily dictated by the underlying Android operating system version.

According to Zimperium’s technical analysis, the malware’s file-encryption module is exclusively functional on devices running Android 9 (Pie) or older versions. This limitation is a direct result of Google’s introduction of "Scoped Storage" in Android 10. The modern privacy and security architecture restricts third-party applications from accessing broad swaths of external storage, effectively neutralizing system-wide file-encryption vectors on contemporary Android builds.

New Android malware encrypts files, steals data, and harasses victims

For vulnerable legacy devices, however, Mantax Otax performs a thorough scan of shared storage directories. It identifies and encrypts specific file types using a unique Advanced Encryption Standard (AES) key fetched directly from the C2 server. Once the encryption process is complete, the original unencrypted files are securely deleted, and the newly encrypted counterparts are appended with a .enc file extension.

To compound the psychological impact, the ransomware script replaces the victim’s local photo gallery images with stark ransom notices. Simultaneously, it launches a full-screen, Firebase-hosted chat interface designed to facilitate direct extortion negotiations between the victim and the operators. Interestingly, operational security lapses by the threat actors exposed these very Firebase communication channels. Security researchers successfully capitalized on a server misconfiguration to inspect the live chat logs, shedding light on the communication dynamics between the attackers and their targets.

Comprehensive Spyware and Surveillance Capabilities

Beyond file encryption, Mantax Otax functions as a robust surveillance tool, deploying an array of spyware features designed to siphon sensitive data from the host device.

The malware maintains persistent access by capturing lock-screen PINs and passwords via deceptive screen overlays, preventing legitimate users from regaining control of their devices without authorization. Once the interface is unlocked or bypassed, the spyware module begins harvesting a vast repository of personal information. This includes reading incoming and outgoing SMS messages, intercepting one-time passwords (OTPs) used for multi-factor authentication, collecting call logs, scraping contact lists, pulling web browsing histories, and compiling exhaustive lists of installed applications. Furthermore, it extracts Google account metadata and tracks real-time location coordinates.

New Android malware encrypts files, steals data, and harasses victims

Popular encrypted messaging platforms are also primary targets. Through the abuse of Accessibility services, Mantax Otax simulates human interactions to extract profile information and message histories from platforms such as WhatsApp and Telegram.

Surveillance is not limited to text-based data. The malware actively abuses Android’s MediaProjection API to capture high-resolution screenshots, record MP4 video files, and stream the victim’s phone screen in near real-time. These recorded files are subsequently exfiltrated via the Catbox file hosting service. In addition to screen recording, the malware can remotely trigger the device’s front and rear cameras to snap unauthorized photographs of the user and their immediate surroundings, uploading the media directly to the attacker-controlled servers.

Psychological Harassment and Intimidation Tactics

In its iterative development, particularly observed in "Version 2" releases, Mantax Otax introduced an aggressive suite of harassment features designed to break down a victim’s resolve. Rather than simply displaying a static ransom note, the malware employs active intimidation mechanisms.

Victims are subjected to a barrage of continuous popup dialog boxes, full-screen intrusive video playbacks, and rapid, disorienting "jumpscare" image overlays designed to render the phone unusable. Furthermore, the malware utilizes remote text-to-speech functionality to broadcast verbal threats and demands aloud through the device speakers at maximum volume. These aggressive operational tactics are intentionally designed to maximize stress, forcing victims to concede to ransom demands out of sheer frustration and fear.

New Android malware encrypts files, steals data, and harasses victims

Broader Industry Impact and Defensive Strategies

The discovery of Mantax Otax underscores the persistent risks associated with sideloading applications from untrusted sources. While modern Android architectures—particularly Android 10 and newer—possess built-in cryptographic safeguards that mitigate the severity of file-encrypting ransomware, the proliferation of hybrid threats combining spyware and remote access Trojans (RATs) continues to pose significant challenges to mobile security ecosystems.

As a member of the App Defense Alliance (ADA) and an official Google security partner, Zimperium shared its threat intelligence swiftly. Consequently, updated Android devices operating with active Google Play Protect services are already equipped to automatically detect and block Mantax Otax installations.

Cybersecurity authorities and mobile defense experts reiterate fundamental hygiene practices to protect against such multi-layered threats. Users are strongly advised to refrain from installing APK files from third-party websites, unverified messaging links, or unofficial app repositories. Additionally, users should exercise extreme caution when applications request sensitive permissions—particularly Accessibility service access—as these permissions are frequently exploited to bypass native operating system security controls. Maintaining an updated operating system remains one of the most effective defenses against legacy-targeted file-encryption routines, ensuring that systemic barriers remain intact against emerging mobile threat vectors.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Device Kick
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.