Threat Intelligence

Mantax Otax: New Android ransomware‑spyware seen in Indonesia

⏱️ 3 min read📅 9/11/2026👁️ 16 views

What Mantax Otax does

After a user clicks a phishing‑laden link and installs a rogue APK, the app immediately asks for Accessibility service permission – a step that gives it deep control over the device.

Once granted, the malware contacts a C2 domain hosted on GitHub, reports location, carrier, Android version and device ID, and then waits for commands delivered via Firebase or WebSockets.

Ransomware side

The ransomware module only runs on Android 9 and older. It fetches a victim‑specific AES key from the C2 server, encrypts files, appends a “.enc” extension and deletes the originals. The infected phone then shows a full‑screen Firebase‑hosted chat where the attacker negotiates payment.

Because Android 10+ enforces Scoped Storage, the encryption routine simply won’t execute on newer devices.

Spyware and harassment

Beyond encryption, the payload gathers basic device telemetry and sends it back to the attackers. Version 2 adds a suite of harassment features – repeated dialog boxes, full‑screen videos, jumpscare overlays and remotely triggered text‑to‑speech messages that play through the speaker.

Who’s at risk

Anyone who sideloads APKs from sources outside Google Play on Android 9 or earlier is a prime target. Up‑to‑date devices with Play Protect enabled will typically detect and block the malware.

Defensive steps

Security researchers recommend three simple habits:

  • Never install APKs from untrusted sites; stick to Google Play whenever possible.
  • Reject Accessibility permission requests from apps that don’t need them.
  • Keep Android and Play Protect current – the latest definitions already flag Mantax Otax.
#Android#Malware#Ransomware#Spyware#Phishing