ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 6 sources: “Google Play 'Early Access' Abuse and Mantax Otax Android Ransomware: Key Developments” — merged summary and timeline →

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

mediumMalware exploited in the wildimportance 46
AI summary · glm-5.3-flash

New Android malware family Mantax OTAX combines ransomware, spyware, and OTP theft via sideloaded APKs, linked to Indonesian threat actors.

Researchers at zLabs and Zimperium analyzed Mantax OTAX, an aggressive Android malware strain distributed as sideloaded APKs through phishing and messaging lures on third-party file-sharing services. The malware requests device-administrator and Accessibility permissions to steal lock-screen PINs, intercept SMS one-time passwords, harvest contacts and history, capture screens via MediaProjection, and silently photograph victims, while encrypting files with AES and writing .enc files on Android 9 and older. Its C2 uses HTTPS at apimantax[.]otax[.]fun with the active domain fetched dynamically from a GitHub repository, and a newer version adds WebSocket communication, app blocking, video overlays, and text-to-speech harassment. A Firebase misconfiguration exposed extortion conversations and victim data, and Android 10+ Scoped Storage limits the encryption reach but not the surveillance capabilities.

  • Steals lock-screen PINs, SMS OTPs, contacts, and location via Accessibility permissions.
  • AES-encrypts files on Android 9 and older, replacing images with ransom graphics.
  • Retrieves active C2 domain from GitHub; Firebase-backed on-device ransom chat exposed.
  • Newer variant uses WebSockets, screen recording, jumpscare overlays, and TTS pressure.
VendorsZimperium
ProductsFirebase
OrganizationszLabsZimperium
CountriesIndonesia

Indicators of compromiseAll →

TypeIndicatorContext
domainapimantax.otax.funMantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published as
urlhttps://apimantax[lution. Mantax OTAX Android Ransomware Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and publ
Full article734 words · extracted from gbhackers.com · click to collapse

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain.

Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion.

Unlike conventional Android ransomware that focuses primarily on locking or encrypting files, Mantax OTAX gives its operators broad visibility into a victim’s digital life before initiating the ransom phase.

The malware can steal lock-screen PINs, intercept SMS messages and one-time passwords, collect browser history, contacts, call logs, installed-app data, Google-account information and location details.

It can also access gallery files, capture images from the device’s cameras, and monitor messaging activity in WhatsApp and Telegram.

Analysed samples were distributed as standalone Android APKs hosted on third-party file-sharing services.

The distribution model relies on phishing, messaging lures and social-engineering tactics to convince targets to install an application outside the official Play Store ecosystem.

This sideloading approach bypasses much of the scrutiny associated with formal app-store publication and remains a recurring delivery mechanism for Android banking trojans and spyware.

After installation, Mantax OTAX requests device-administrator privileges, followed by permissions for SMS, contacts, audio and images.

It ultimately seeks Android Accessibility access, a high-risk permission that enables malware to observe and manipulate screen content, automate interaction with applications and harvest sensitive data displayed to the user.

The malware communicates with its command-and-control infrastructure over HTTPS and retrieves its active C2 domain from a GitHub repository.

Victim’s device before and after the ransomware attack (Source : zLabs).
Victim’s device before and after the ransomware attack (Source : zLabs).

This dynamic resolution mechanism allows the operators to change infrastructure if a domain is blocked without distributing a newly compiled APK.

The zLabs research team has discovered a Android malware, sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution.

Mantax OTAX Android Ransomware

Zimperium identified hxxps://apimantax[.]otax[.]fun as a C2-related domain in its analysis and published associated indicators in its public IOC repository.

Under the guise of this necessary administrative activity, the malware restricts user access to the device and intercepts the user’s lock screen PIN.

Malware showing system lock overlay on top of screen (Source : zLabs).
Malware showing system lock overlay on top of screen (Source : zLabs).

Mantax OTAX requests a unique encryption key from its C2 server using the victim device’s Android ID.

On Android 9 and older releases, it recursively searches shared external storage for documents, images, videos, archives, databases and cryptographic-key material.

The malware uses AES encryption, deletes original content and writes encrypted replacements with a .enc extension.

The ransomware deliberately avoids the Android/data and Android/obb directories, likely reducing the chance of destabilizing the device.

It then replaces selected local images with ransom-themed graphics containing the message: “Your files have been encrypted.

Pay to decrypt.” An on-device chat portal is subsequently displayed, enabling direct negotiations between the operators and victims through Firebase-backed communications.

Researchers said a Firebase misconfiguration exposed extortion conversations and other victim-related data.

Android 10 and later substantially reduce the ransomware module’s file-encryption reach through Scoped Storage.

However, that protection does not neutralize the malware’s surveillance, OTP theft, account takeover and device-disruption capabilities.

Mantax OTAX abuses Android’s MediaProjection API to capture screenshots, record MP4 video and stream screen content.

Screenshots are compressed and uploaded to the Catbox file-hosting service, while generated URLs are sent back to the operators. The malware can also silently take photographs with the front or rear camera.

The latest version of malware using websocket communication (Source : zLabs).
The latest version of malware using websocket communication (Source : zLabs).

A newer Mantax OTAX version uses WebSockets and introduces coercive controls including app blocking, transparent touch-blocking overlays, repeated dialog spam, full-screen video overlays, “jumpscare” image pop-ups and remote text-to-speech playback.

These features can obstruct recovery attempts while increasing psychological pressure on victims.

The campaign illustrates an important shift in mobile extortion: encryption is no longer the sole leverage point.

By pairing data theft, OTP interception, credential capture, continuous screen monitoring and device control with ransomware, operators can pursue double-extortion tactics even where modern Android storage protections limit file encryption.

Users should avoid APKs from untrusted links, keep Android and Play Protect updated, and treat unexpected Accessibility or device-administrator requests as a compromise warning.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/mantax-otax-android-ransomware/