Mantax Otax: New Indonesian Mobile Ransomware with Spyware Capabilities

Mantax Otax: New Indonesian Mobile Ransomware with Spyware Capabilities

First seen 9 Sep 2026, 21:13 UTC Zimperium 66.5

Article Content

Browse articles
ThreatCluster

The zLabs research team has identified a new mobile malware strain named Mantax Otax, linked to Indonesian threat actors. This malware combines ransomware and spyware functionalities, compromising user privacy by recording screens, extracting browser history, and stealing sensitive information. It targets older Android versions by encrypting data and demanding ransom through an interactive chat interface post-infection. The malware is distributed as a standalone APK via third-party file-sharing services, utilizing social engineering tactics to encourage installation. Upon installation, it requests extensive permissions, including device administrator rights, to gain control over the device. Communication with its Command and Control (C2) server is secured via HTTPS, and it employs a dynamic domain resolution mechanism to maintain operational resilience. The malware's sophisticated nature poses a significant threat to users, particularly those using outdated Android systems.

Key Points: • Mantax Otax integrates ransomware and spyware, targeting older Android devices. • The malware is distributed via third-party APKs, leveraging social engineering tactics. • It employs a dynamic C2 resolution mechanism to evade detection and maintain control.

Ask AI about this cluster

Timeline

2026-09-09
Mantax Otax identified
zLabs discovered a new mobile malware strain linked to Indonesian actors, combining ransomware and spyware features.
Zimperium
2026-09-09
Malware distribution method revealed
The malware is distributed as a standalone APK on third-party file-sharing services, bypassing app store security.
Zimperium
2026-09-09
C2 communication mechanism detailed
The malware uses HTTPS for secure communication and a dynamic domain resolution for C2 servers.
Zimperium