What Mantax Otax does
After a user clicks a phishing‑laden link and installs a rogue APK, the app immediately asks for Accessibility service permission – a step that gives it deep control over the device.
Once granted, the malware contacts a C2 domain hosted on GitHub, reports location, carrier, Android version and device ID, and then waits for commands delivered via Firebase or WebSockets.
Ransomware side
The ransomware module only runs on Android 9 and older. It fetches a victim‑specific AES key from the C2 server, encrypts files, appends a “.enc” extension and deletes the originals. The infected phone then shows a full‑screen Firebase‑hosted chat where the attacker negotiates payment.
Because Android 10+ enforces Scoped Storage, the encryption routine simply won’t execute on newer devices.
Spyware and harassment
Beyond encryption, the payload gathers basic device telemetry and sends it back to the attackers. Version 2 adds a suite of harassment features – repeated dialog boxes, full‑screen videos, jumpscare overlays and remotely triggered text‑to‑speech messages that play through the speaker.
Who’s at risk
Anyone who sideloads APKs from sources outside Google Play on Android 9 or earlier is a prime target. Up‑to‑date devices with Play Protect enabled will typically detect and block the malware.
Defensive steps
Security researchers recommend three simple habits:
- Never install APKs from untrusted sites; stick to Google Play whenever possible.
- Reject Accessibility permission requests from apps that don’t need them.
- Keep Android and Play Protect current – the latest definitions already flag Mantax Otax.
