Skip to content
MantaxOtax Android Malware Combines Ransomware With Spyware

MantaxOtax Android Malware Combines Ransomware With Spyware

Infosecurity-Magazine September 10, 2026

MantaxOtax Android malware has combined file encryption with extensive surveillance, letting attackers steal messages, credentials and device data while restricting access to infected phones.

In a technical write up published on September 9, Zimperium's zLabs team linked the malware to Indonesian threat actors and said some samples appeared to have been distributed as a standalone Android package on a third-party file-sharing service, pointing to a sideloading route.

The Mobile Ransomware Side

After installation, MantaxOtax requested device administrator privileges, then access to SMS, contacts, audio and images and finally Android Accessibility , which gave it broad control over device interactions.

The malware resolves its live command-and-control (C2) domain from a GitHub repository, which Zimperium said lets the operators move to new infrastructure without changing code if a domain is blocked.

On Android 9 and earlier, the mobile ransomware recursively scanned shared external storage, encrypted user files with AES, purged the originals from disk and left .enc copies. Each key is fetched from the C2 against the device's Android ID, so no two victims one.

On Android 10 and later, Scoped Storage confined the scan to the app's own external files directory, sharply reducing what could be encrypted. Zimperium said the malware also overwrote the victim's own image files with ransom graphics to make the demand unmissable.

An on-screen chat interface then opened for negotiation. Zimperium said those exchanges ran through Firebase and that a server misconfiguration left some extortion dialogues exposed.

A separate routine masqueraded as a system lock process, restricting access while intercepting the lock screen PIN.

MantaxOtax Adds Remote Monitoring and Device Control

The mobile spyware side collected app inventories, hardware details, location, browser history, notifications, contacts, call logs and SMS messages including one-time passwords (OTPs), plus gallery content and linked Google accounts. It also pulled WhatsApp profiles and messages through Accessibility, and Telegram credentials and chat histories.

The malware abused Android's MediaProjection API for screenshots, MP4 screen recording and near-real-time streaming, staging captures on the Catbox file host and sending the links back to its operators. It could also take silent photos on either camera.

Zimperium said language indicators and recovered victim files suggested Indonesian targeting, and that the misconfigured server also yielded a screenshot of what appeared to be the operators' control panel.

A second version moved to WebSocket communications and added persistent screen locking, application blocking and a transparent overlay that swallows all touch input.

Others are built purely to wear the victim down: repeating alert dialogues, full-screen video overlays, image popups spawning every 600 milliseconds, and text-to-speech (TTP) that makes the handset speak the attacker's words aloud.

MantaxOtax follows THost9, an Android trojan reported this week that cloned banking apps into an isolated work profile to break the link between a malware alert and the fraud that followed.

RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026

RedWing Android Spyware Sold as a Service on Telegram

Rokarolla Trojan Combines Banking Fraud With Device Surveillance News 16 June 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users News 20 May 2026

Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users

Financial Brands Targeted in Global Mobile Banking Malware Surge News 19 March 2026

Financial Brands Targeted in Global Mobile Banking Malware Surge

PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time News 12 March 2026

PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

NCSC Warns Shadow AI Creates New Security Risks

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

NCSC Warns Shadow AI Creates New Security Risks

FBI Probes Possible Breach of 153 Million Driver’s Licenses

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How To Enhance Security Operations with AI-Powered Defenses

Why Resilience‑Focused Cloud Design Is Your Best Defense Against Modern Attacks

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust