New Mantax Otax Android Malware Combines Ransomware, Spyware and Harassment

Last updated: September 11, 2026 Reading time: 5 minutes
Disclosure
Share
New Android Malware Combines Ransomware, Spyware and Psychological Harassment
  • Mantax Otax is an Android malware strain operated by Indonesian threat actors that fuses file encryption, extensive data surveillance, and psychological harassment features into a single payload.
  • The ransomware module encrypts shared storage files using Advanced Encryption Standard keys on older Android 9 devices, while native Scoped Storage rules protect Android 10 and newer versions.
  • The malware intercepts one-time passwords, records screen activity via MediaProjection APIs, extracts chat logs from messaging platforms, and uses text-to-speech overlays to pressure victims.

Cybersecurity experts have discovered a harmful new type of Android malware referred to as Mantax Otax. The threat combines ransomware file encryption and advanced spyware capabilities. Threat actors from Indonesia deliver the malware via independent package files located on third-party web-pages away from official app marketplaces.

The malicious actors use extensive deception techniques such as previous social engineering and targeted phishing emails to lure unsuspecting users to install the malware application on their device voluntarily. Once activated on a device, the application requests extensive permissions to gain total control over the compromised operating system.

Operational Infrastructure and Command Resolution Mechanics

After successful installation, Mantax Otax immediately prompts the user to enable Android Accessibility Services. Securing access to this core helper framework gives the program elevated administrative privileges across the entire device environment. Subsequently, the program connects to an external GitHub repository to retrieve its active command-and-control server domain.

A compromised mobile device sends telemetry information about its hardware back to an external server. Some sent telemetry includes information about the location of the device, network carrier, Android operating system version, and device IDs.

Operators then issue execution instructions through Firebase channels or persistent WebSocket connections. Furthermore, security firm Zimperium discovered a misconfiguration in the attackers’ Firebase server layout, exposing live ransom negotiation logs between operators and victims.

Technical Execution of Encryption on Legacy Android Builds

The ransomware module specifically targets mobile devices running legacy operating systems, specifically Android 9 and older builds. On these older systems, the code scans shared external storage directories to locate personal documents, photos, and media assets. The program fetches a unique Advanced Encryption Standard key from its control server to encrypt target files.

After that, it removes the original unencrypted files and adds an appropriate extension to the encrypted files that were encrypted. The software makes the images in the gallery disappear and replaces the images with a ransom note. Also, it opens a chat window with the use of Firebase to talk about the payment.

On the contrary, the devices operating on Android 10 or newer versions are not affected by the malware. This is because these versions have the native Scoped Storage technology which prevents modification of external files.

While Scoped Storage protects system spaces in modern devices from destruction, users of old devices will lose all of their data since the devices will stop working. Meanwhile, organizational cybersecurity resources recommend keeping mobile hardware updated to benefit from modern operating system storage protections.

Deep Surveillance Capabilities and Data Exfiltration Engine

Beyond file encryption, Mantax Otax operates as a comprehensive spyware package designed to extract sensitive user information. The payload steals lock-screen PIN codes using fake system overlays to maintain persistent administrative access.

Additionally, it reads incoming text messages, intercepts one-time verification passwords, and accesses call logs. Also, it harvests contacts, extracts browsing histories, and tracks real-time location coordinates.

In addition, the program exploits Accessibility Services to create the impression of users touching the screen. Thus, it receives a chance to open chats discreetly. With the help of these clicks, the malware retrieves personal data and private chats from various applications, such as WhatsApp and Telegram. Moreover, it utilizes the Android MediaProjection application programming interface to record screen activity, take screenshots, and stream live display feeds.

In September 2026, a threat actor claimed to have accessed a database from Colombia’s Cali government containing more than 600,000 records and 60 GB of data. The alleged data covered public finance and tax systems, but Colombian authorities have not confirmed the breach.

The software uploads captured media directly to public file hosting services like Catbox for operator viewing. In addition, it can remotely trigger the front and rear cameras to take secret photographs of the victim’s surroundings. Subsequently, after the stolen pictures move to the remote servers, the criminals receive the collateral to use for their blackmail schemes.

Psychological Intimidation Tactics and Protection Measures

The upgraded version of Mantax Otax comes with very aggressive harassment methods, targeted at frightening its victim into paying ransom. The malware triggers rapid dialog boxes, displays full-screen videos, and overlays unexpected jump-scare images across the screen.

Moreover, operators can send remotely controlled text-to-speech messages that play loudly through the device speakers to create continuous psychological pressure.

Fortunately, Google Play Protect detects and blocks known variants of Mantax Otax on updated Android devices. The best defense against hybrid mobile threats lies in steering clear of manual software installations from untrustworthy links.

In addition, users should implement regular auditing of installed apps and ensure that the device firmware is always current. Also, they should rely solely on authorized app stores for all downloads. Maintaining good digital hygiene are critical abatement measure against malicious software from establishing persistent surveillance roots across personal mobile devices.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts