A sophisticated new Android malware strain, Mantax Otax, is combining ransomware and spyware to encrypt user files, steal sensitive data, and psychologically harass victims through 'jumpscares' and screen recording.

  • Mantax Otax integrates ransomware, spyware, and psychological harassment tools.
  • It specifically targets Android 9 and older versions for full file encryption.
  • The malware leverages Accessibility services to gain total device control and steal credentials.

A dangerous new threat has emerged in the mobile ecosystem known as Mantax Otax. Developed by operators based in Indonesia, this malware is a hybrid threat that blends the destructive nature of ransomware with the stealth of spyware. Unlike traditional malware that simply locks files for money, Mantax Otax aims to intimidate and psychologically pressure its victims.

According to research from Zimperium, the malware is distributed via malicious APKs hosted outside the official Google Play Store. Attackers employ sophisticated phishing and social engineering tactics to trick users into installing the software. Once installed, the malware requests access to the device's Accessibility services, granting it the ability to simulate user interactions and intercept sensitive data.

Technical Execution and Data Exfiltration

The malware retrieves its command-and-control (C2) infrastructure domain from GitHub, sending back critical victim data including location, carrier, and device ID. The ransomware module is specifically tuned for Android 9 and older. This is because Android 10 introduced 'Scoped Storage,' a security feature that prevents apps from accessing shared storage indiscriminately, thereby neutralizing the malware's encryption capabilities on newer devices.

"Mantax Otax represents a shift toward 'psychological warfare' in mobile malware, using intimidation as a primary lever for ransom payments."

Why This Matters

BozokMedia analysis shows that the most alarming aspect of Mantax Otax is its harassment module. Version 2 of the malware includes the ability to trigger rapid 'jumpscare' image overlays, play remotely controlled text-to-speech messages, and stream the victim's screen in real-time via the Catbox hosting service. This creates a state of constant panic for the user, making them more likely to pay the ransom.

Feature Android 9 & Older Android 10 & Newer
File Encryption Fully Capable Severely Restricted
Data Spying Active Active (via permissions)
Ransom Notes Full-screen Overlay Limited Impact

Beyond encryption, the spyware module can steal lock-screen PINs, read SMS/OTPs, access call logs, and extract messages from WhatsApp and Telegram. Fortunately, as Zimperium is a Google security partner, the malware is currently detected and blocked by updated Android devices with an active Play Protect service.

Did You Know?: The 'Scoped Storage' feature in Android 10 was specifically designed to stop apps from 'seeing' files created by other apps, which is why this ransomware fails on newer phones.

Frequently Asked Questions

Q1: Is my device at risk?
If you use Android 10 or later and only install apps from the Google Play Store, your risk is minimal. However, avoid granting 'Accessibility' permissions to unknown apps.

Q2: How can I protect myself from such threats?
Always keep your OS updated, enable Google Play Protect, and never download APKs from third-party websites or phishing links.