Mantax Otax Android Malware Encrypts Files, Spies on Victims, and Weaponizes Harassment
Malware

Illustrative image generated with AI

Mantax Otax Android Malware Encrypts Files, Spies on Victims, and Weaponizes Harassment

Mantax Otax Android malware encrypts files on Android 9 or older, steals SMS, screen data, and harasses victims. Distributed via APKs outside Google Play.

Text generated by artificial intelligence, published without human review. AI transparency

A newly identified Android malware strain called Mantax Otax combines ransomware, account surveillance, remote device control, and tools designed to intimidate victims.

Details reported on September 10, 2026, show that the malware is distributed through malicious APK files hosted outside Google Play. Its operators, described as Indonesian, use phishing and social-engineering messages to convince targets to install the applications and grant powerful Accessibility permissions.

Mantax Otax is especially destructive on devices running Android 9 or earlier, where it can encrypt files across shared storage. Android 10 and later restrict that capability through Scoped Storage, but newer devices remain exposed to the malware’s spying, screen-capture, camera, and harassment functions.

Accessibility access turns a malicious APK into a remote-control tool

The infection chain requires the victim to install an APK from outside Android’s official application store. The malicious application then requests access to Android’s Accessibility service.

That permission is central to the operation. Accessibility features are intended to help users interact with applications, but malware can abuse them to observe interface content and simulate taps, typing, and navigation.

Mantax Otax uses this control to collect data from applications and perform actions that would ordinarily require direct user interaction. It can access messages, capture information displayed on screen, and operate surveillance features under instructions from its command-and-control infrastructure.

The malware does not rely exclusively on a C2 address embedded inside the APK. Instead, it retrieves the current infrastructure domain from GitHub, giving operators a mechanism to change servers without necessarily distributing a new malware build.

After connecting, Mantax Otax reports information about the victim and device. Command delivery and communications may then take place through Firebase or WebSockets.

The exact malicious package names, signing certificates, hashes, C2 domains, and phishing lures have not been disclosed. That limits defenders’ ability to rely on static indicators alone.

File encryption is most effective on Android 9 and older

The ransomware component searches shared storage for selected file types. For each victim, it obtains a specific AES encryption key from the C2 server and uses that key to encrypt targeted files.

Mantax Otax deletes the originals and adds the extension .enc to encrypted copies. It can also replace images stored on the device with ransom notices, making the extortion demand visible throughout the victim’s photo collection.

The malware then opens a full-screen chat interface hosted through Firebase. Victims can use this interface to communicate and negotiate ransom payments directly with the operators.

Zimperium researchers found a configuration error in the attackers’ Firebase infrastructure and used it to access conversations between operators and victims, exposing communications connected to the extortion campaign.

The encryption module operates against Android 9 or older. Devices running Android 10 and later benefit from Scoped Storage, which limits how applications can access files belonging to other applications and locations outside their permitted external-files directory.

That protection substantially reduces the malware’s capacity to encrypt files across shared storage. It does not neutralize the infection.

On newer Android releases, Mantax Otax can still steal information, automate interactions, capture screens, activate cameras, and deliver disruptive content if it obtains the necessary permissions.

Surveillance extends from SMS messages to cameras and live screens

Mantax Otax collects a broad range of personal and technical information. Its capabilities include stealing:

  • The device’s lock-screen PIN.
  • SMS messages and one-time passwords.
  • Contacts and call logs.
  • Browsing history.
  • Lists of installed applications.
  • Google account information.
  • Device location.
  • The device identifier, carrier, and Android version.

Access to SMS messages and one-time passwords creates risks beyond the infected phone. Stolen codes may help attackers interfere with accounts whose authentication process depends on text messages, while a captured lock-screen PIN can support continued access to the device.

The malware can also obtain WhatsApp profiles and messages, along with Telegram conversations. It uses Accessibility-driven interaction to navigate and extract content rather than depending solely on direct access to application storage.

For visual surveillance, Mantax Otax abuses Android’s MediaProjection API. It can capture screenshots, record the display as MP4 video, and provide near-real-time screen monitoring through the Catbox file-hosting service.

Operators can additionally activate the phone’s cameras, take photographs, and upload the resulting images. A compromised device can therefore expose both on-screen activity and the victim’s physical surroundings.

These features make the threat relevant even when file encryption fails. A device running Android 10 or later may avoid the most extensive ransomware damage while still leaking private conversations, credentials, location data, and visual recordings.

Version 2 adds tools for intimidation and psychological pressure

Version 2 of Mantax Otax introduced features intended to harass victims during extortion. The malware can repeatedly display dialog boxes, force full-screen video playback, and rapidly overlay “jumpscare” images.

Operators can also send text that the infected device reads aloud through its speakers using text-to-speech functionality. This gives the attacker a direct and disruptive channel into the victim’s environment.

The harassment layer differentiates Mantax Otax from Android ransomware that simply encrypts files and displays a payment demand. Here, the operators can combine stolen personal information, device surveillance, persistent interruptions, and audiovisual intimidation.

That combination may increase pressure on victims by demonstrating that the attackers retain control of the phone. It also means that the consequences are not limited to data availability: privacy, account security, and personal safety may all be affected.

No information has been disclosed about the number of victims, requested ransom amounts, payment methods, campaign start date, or geographic scope beyond the description of the operators.

Warning signs include sideloading, Accessibility prompts, and .enc files

The clearest prevention measure is to avoid installing APK files received through unsolicited messages or downloaded from untrusted websites. Mantax Otax depends on distribution outside Google Play and requires the victim to complete the installation process.

Users should treat an unexpected request for Accessibility access as a serious warning, particularly when the application’s stated function does not justify control over screen content and interface actions.

Potential signs of compromise include:

  • An unfamiliar sideloaded application with Accessibility access.
  • Files unexpectedly renamed with the .enc extension.
  • Images replaced by ransom messages.
  • Unexplained full-screen chats, videos, dialog boxes, or image overlays.
  • Spoken messages generated through the device speakers.
  • Unexpected screen-recording or MediaProjection prompts.
  • Camera activity that the user did not initiate.

Because no package identifiers or file hashes are available, security teams should examine permissions and behavior rather than waiting for a single known indicator.

Play Protect blocks the threat, but Android updates still matter

Zimperium participates in Google’s App Defense Alliance, and Mantax Otax is already detected and blocked on up-to-date Android devices where Google Play Protect is enabled.

Users should verify that Play Protect remains active, keep Android and its security components updated, and install applications only from reputable publishers. Application permissions should match the software’s legitimate purpose.

Organizations managing Android fleets should also monitor sideloading and review which applications hold Accessibility privileges. Devices running Android 9 or earlier face the greatest file-encryption risk and should be upgraded where possible.

The principal defenses are straightforward: avoid untrusted APKs, reject suspicious Accessibility requests, maintain current security protections, and scrutinize messages that attempt to move software installation outside Google Play.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsMantax OtaxAndroid malwareransomwarespywareAccessibility abuseAPKharassment
Back to home