A newly identified Android malware called Mantax Otax combines ransomware and spyware in a single package. Instead of only locking files and demanding payment, the malware can also monitor activity, steal verification codes, capture screens, and secretly access the device camera.
The campaign appears to target users who install Android applications from unofficial sources. Attackers distribute malicious APK files through file-sharing platforms, messaging services, phishing messages, or other links outside the official app stores.
Researchers associated the activity with Indonesian threat actors and found several indicators suggesting a focus on Indonesian users. The discovery highlights a growing risk for mobile users: a single malicious application can now be used for both extortion and surveillance.
How Mantax Otax Takes Control of an Android Device
After installation, the malware requests powerful permissions, including device administrator and Accessibility access. These permissions allow it to perform actions on the device and collect sensitive information.
On older Android versions, the malware can search shared storage for files such as:
- Photos and videos
- Documents
- Other user files
- Cryptographic keys
It can encrypt selected files using AES, replace the originals with encrypted versions, and add an .enc extension. A ransom message can then be displayed to the victim.
Newer Android versions provide stronger storage restrictions, which can limit the malware’s ability to encrypt files outside its own application area. However, this does not eliminate the spyware risk.
Mantax Otax can abuse Android’s MediaProjection functionality to capture screenshots and record the screen. It can also stream screen activity and send captured information to its operators.
The malware is capable of secretly activating either camera and taking photographs without obvious interaction from the victim.
It can also collect a broad range of information, including:
- SMS messages and notification content
- Contacts and call information
- Browser history
- Location information
- Installed applications
- Device details
- Gallery data
- Google account-related information
OTP Theft Creates an Account-Takeover Risk
One of the most serious capabilities is the theft of one-time passwords (OTPs).
By monitoring SMS messages and notifications, Mantax Otax can potentially capture verification codes used for multi-factor authentication. This could help attackers gain access to online accounts when combined with stolen credentials.
The malware also targets messaging applications such as WhatsApp and Telegram. Through Accessibility abuse, it can interact with applications and access conversations or account information.
Another technique involves displaying a fake system-lock screen. The malware can make the screen appear locked and capture the PIN entered by the victim.
A newer version reportedly adds additional capabilities, including WebSocket-based communication, application blocking, touch-blocking overlays, pop-ups, full-screen content, and remote text-to-speech messages.
For Android users, the safest approach is to avoid installing APK files from unknown sources. Users should also carefully review permission requests and avoid granting powerful access when it does not match the application’s purpose.
Organizations managing mobile devices should monitor for:
- Sideloaded applications
- Unexpected Accessibility permissions
- Unusual screen-capture activity
- Suspicious device-administrator access
- Unexpected outbound connections
If a phone suddenly displays an unfamiliar lock screen, repeated permission requests, or unusual overlays, users should disconnect it from networks and seek trusted technical assistance before entering passwords or PINs.
Mantax Otax shows how Android malware is becoming more versatile. Combining ransomware, surveillance, and credential theft allows attackers to turn one compromised phone into both a source of sensitive information and a potential entry point into other accounts.