ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 6 sources: “Google Play 'Early Access' Abuse and Mantax Otax Android Ransomware: Key Developments” — merged summary and timeline →

New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

mediumRansomwareimportance 45
AI summary · glm-5.3-flash

Zimperium uncovered Mantax Otax, an Android ransomware that encrypts files, records screens, steals OTPs, and secretly photographs victims.

Zimperium reported a new Android threat, Mantax Otax, that combines ransomware with surveillance: it encrypts files with AES and adds a .enc extension on Android 9 and older, while abusing MediaProjection for screenshots and MP4 screen recording and using hidden camera previews to photograph victims. The malware intercepts SMS one-time passwords, WhatsApp and Telegram data, and lock-screen PINs through Accessibility abuse and a fake system-lock overlay, and can negotiate ransoms via an on-screen chat. Malicious APKs are hosted on third-party file-sharing services, and researchers linked the activity to Indonesian threat actors, with C2 dynamically retrieved from a GitHub repository (apimantax[.]otax[.]fun). A second variant adds WebSocket communications, app blocking, full-screen overlays, and remote text-to-speech messages.

  • Encrypts files with AES on Android 9 and older, deletes originals, and adds a .enc extension.
  • Abuses MediaProjection for screenshots and video, uploading captures to Catbox.
  • Intercepts SMS OTPs, WhatsApp and Telegram data via Accessibility and a fake lock overlay that captures the PIN.
  • Linked to Indonesian threat actors; second version adds WebSocket C2 and disruptive overlays.

Indicators of compromiseAll →

TypeIndicatorContext
domainapimantax.otax.funbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved
urlhttps://apimantax[cted outbound traffic. Type Indicator Description C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically r
Full article802 words · extracted from cybersecuritynews.com · click to collapse

A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links.

Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s cameras, making one infection both an extortion and privacy crisis.

The campaign appears built around standalone Android app packages, or APKs, hosted on third-party file-sharing services.

Victims can be led to them through shared links, messaging apps or phishing messages, then persuaded to install the app outside the official store.

Its researchers linked the activity to Indonesian threat actors and found language clues and victim files suggesting an Indonesian focus. The discovery shows how mobile criminals are bringing surveillance, account theft and file encryption together in one package.

Zimperium said in a report shared with Cyber Security News (CSN) that the impact can go far beyond losing access to photos or documents.

Stolen SMS one-time passwords, chats and lock-screen PINs can give criminals the information needed to enter accounts or pressure victims. The combination resembles other Android OTP theft campaigns that turn a compromised phone into an account-takeover tool.

New Android Ransomware

After installation, Mantax Otax asks for device-administrator rights and then seeks access to SMS, contacts, audio and images.

It ultimately asks for Accessibility access, a legitimate Android feature designed to assist users but one that can be abused to read screen content and perform actions. This permission path is also central to the Crocodilus Android banking threat.

Malicious APKs are hosted on a third-party file-sharing platform (Source - Zimperium)
Malicious APKs are hosted on a third-party file-sharing platform (Source – Zimperium)

On Android 9 and older versions, the ransomware searches shared external storage for images, videos, documents and cryptographic keys.

It encrypts targeted files with AES, deletes the originals and adds the .enc extension to the replacements. It also overwrites local images with a ransom notice telling victims their files were encrypted and must be paid for.

The damage is more limited on Android 10 and later because Scoped Storage restricts the app mostly to its own external-files area.

However, that restriction does not remove the surveillance danger. Following encryption, the malware can display an on-screen chat function that lets attackers negotiate a ransom directly, creating conditions for double extortion.

Permission requested by the malware (Source - Zimperium)
Permission requested by the malware (Source – Zimperium)

Mantax Otax also abuses Android’s MediaProjection function to take screenshots, record the screen as MP4 video and stream display content almost in real time.

Captured screenshots are uploaded to Catbox before associated URLs return to the operators. Similar screen-viewing abuse appeared in the recent StreamRAT mobile campaign, where operators could watch and manipulate victims’ phones.

The spyware component can additionally open either camera through a hidden preview surface and take photographs without visible interaction. The image is compressed, stored locally, encoded and sent to the attacker.

OTP Theft Raises Account Risks

The malware gathers contacts, call logs, browser history, location data, installed apps, device information, linked Google-account settings and gallery files.

It monitors notifications and inbound SMS messages, placing multi-factor authentication codes at risk. It also targets WhatsApp profiles and messages, plus Telegram credentials and chat history, using Accessibility-driven clicks to open conversations.

A fake system-lock overlay adds another route to credential theft. Mantax Otax presents itself as a necessary lock process, blocks access and captures the PIN a victim enters.

Victim’s device before and after the ransomware attack (Source - Zimperium)
Victim’s device before and after the ransomware attack (Source – Zimperium)

Its second version adds WebSocket communications, app blocking, a transparent layer that absorbs touch input, disruptive pop-ups, full-screen video overlays and remote text-to-speech messages.

The practical defense begins before an app is installed. People should avoid APKs promoted through unsolicited messages, social posts and unfamiliar file-sharing links, and install software through trusted stores.

They should reject Accessibility, administrator, SMS, screen-capture or camera permissions that do not match an app’s purpose, a precaution reinforced by reporting on fake Android apps stealing PINs.

Anyone who sees an unfamiliar lock screen, persistent overlay or unexpected permission request should disconnect the phone from networks and seek trusted support before entering passwords or PINs.

Organisations should watch managed devices for sideloaded apps, unusual Accessibility activation, screen-capture requests and unexpected outbound traffic.

TypeIndicatorDescription
C2 domainhxxps://apimantax[.]otax[.]funActive command-and-control domain dynamically retrieved by Mantax Otax from a GitHub repository. 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/new-android-ransomware/