Back Infosecurity-Magazine MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware has combined file encryption with extensive surveillance, letting attackers steal messages, credentials and device data while restricting access to infected phones.
In a technical write up published on September 9, Zimperium's zLabs team linked the malware to Indonesian threat actors and said some samples appeared to have been distributed as a standalone Android package on a third-party file-sharing service, pointing to a sideloading route.
The Mobile Ransomware Side
After installation, MantaxOtax requested device administrator privileges, then access to SMS, contacts, audio and images and finally Android Accessibility , which gave it broad control over device interactions.
The malware resolves its live command-and-control (C2) domain from a GitHub repository, which Zimperium said lets the operators move to new infrastructure without changing code if a domain is blocked.
On Android 9 and earlier, the mobile ransomware recursively scanned shared external storage, encrypted user files with AES, purged the originals from disk and left .enc copies. Each key is fetched from the C2 against the device's Android ID, so no two victims one.
On Android 10 and later, Scoped Storage confined the scan to the app's own external files directory, sharply reducing what could be encrypted. Zimperium said the malware also overwrote the victim's own image files with ransom graphics to make the demand unmissable.
An on-screen chat interface then opened for negotiation. Zimperium said those exchanges ran through Firebase and that a server misconfiguration left some extortion dialogues exposed.
A separate routine masqueraded as a system lock process, restricting access while intercepting the lock screen PIN.
MantaxOtax Adds Remote Monitoring and Device Control
The mobile spyware side collected app inventories, hardware details, location, browser history, notifications, contacts, call logs and SMS messages including one-time passwords (OTPs), plus gallery content and linked Google accounts. It also pulled WhatsApp profiles and messages through Accessibility, and Telegram credentials and chat histories.
The malware abused Android's MediaProjection API for screenshots, MP4 screen recording and near-real-time streaming, staging captures on the Catbox file host and sending the links back to its operators. It could also take silent photos on either camera.
Zimperium said language indicators and recovered victim files suggested Indonesian targeting, and that the misconfigured server also yielded a screenshot of what appeared to be the operators' control panel.
A second version moved to WebSocket communications and added persistent screen locking, application blocking and a transparent overlay that swallows all touch input.
Others are built purely to wear the victim down: repeating alert dialogues, full-screen video overlays, image popups spawning every 600 milliseconds, and text-to-speech (TTP) that makes the handset speak the attacker's words aloud.
MantaxOtax follows THost9, an Android trojan reported this week that cloned banking apps into an isolated work profile to break the link between a malware alert and the fraud that followed.
RedWing Android Spyware Sold as a Service on Telegram News 8 July 2026
RedWing Android Spyware Sold as a Service on Telegram
Rokarolla Trojan Combines Banking Fraud With Device Surveillance News 16 June 2026
Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users News 20 May 2026
Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users
Financial Brands Targeted in Global Mobile Banking Malware Surge News 19 March 2026
Financial Brands Targeted in Global Mobile Banking Malware Surge
PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time News 12 March 2026
PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
NCSC Warns Shadow AI Creates New Security Risks
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
NCSC Warns Shadow AI Creates New Security Risks
FBI Probes Possible Breach of 153 Million Driver’s Licenses
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Why Resilience‑Focused Cloud Design Is Your Best Defense Against Modern Attacks
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
