News

Mantax Otax Android malware mixes ransomware and spyware

Zimperium zLabs (Vishnu Pratapagiri, 9 September 2026) describes Mantax Otax as a sideloaded Android hybrid that pairs spyware with AES ransomware and a Firebase extortion chat. Encryption on Android 9 and earlier can walk shared storage. Android 10 and later Scoped Storage largely confines the scan to the app's own folder.

Mantax Otax Android malware mixes ransomware and spyware

Zimperium zLabs (Vishnu Pratapagiri, 9 September 2026) described Mantax Otax as a hybrid Android family that stacks a spyware suite, file encryption, and an on-device chat for ransom talks. Language and recovered files point to Indonesian targeting.

This is a vendor security research blog. It is not a CVE, not a CISA Known Exploited Vulnerabilities listing, and not a Google Play advisory. Samples in the report arrive as standalone APKs on third-party file sharing. Infection is sideloading after phishing or social engineering, not a Play Store listing and not a zero-click worm.

After install the malware asks for device admin, then SMS, contacts, audio, and images, then Accessibility. It pulls its command-and-control domain from a GitHub repo (the report's example is apimantax.otax.fun), then registers the device over HTTPS with geo, carrier, and Android version.

Encryption uses a victim-specific AES key from the C2. Originals are deleted and copies get a .enc extension. On Android 9 and earlier the scan walks shared external storage, skipping Android/data and Android/obb. On Android 10 and later, Scoped Storage largely confines that ransomware scan to the app's own external-files directory.

After encryption, a Firebase-hosted chat opens for negotiation. A misconfigured Firebase instance exposed attacker-victim dialogues to the researchers.

BleepingComputer (Bill Toulas, 10 September 2026) and other secondaries reading a leaked panel screenshot have cited about 210 enrolled devices with two online at capture. That is a panel snapshot, not a census. Victim scale beyond that frame is not verified in the Zimperium writeup.

The spyware side steals lock-screen PINs through a fake system lock overlay, plus SMS and OTPs, call logs, contacts, browser history, and WhatsApp and Telegram via Accessibility. MediaProjection captures screenshots, MP4s, and a live stream staged through Catbox. Silent front and rear camera photos go out as well. Mantax v2 adds WebSockets, dialog spam, video overlays, jumpscare overlays about every 600 ms, remote text-to-speech through the speakers, and touch-blocking overlays.

BleepingComputer notes that Zimperium's App Defense Alliance partnership means Play Protect already detects samples on up-to-date devices with the service active. The research does not show a Google Play store compromise.

Related Android and extortion tape includes WeWorm's WeChat zero-click worm, Mullvad's Android NAT-T VPN leak, WatchGuard Firebox RCE used in ransomware, and IDscan's 150 million licenses breach.

If you handle Android fleets in Indonesia or review sideloaded APKs, treat Android 9 and earlier as the ransomware blast radius, keep Play Protect on, and refuse device-admin and Accessibility grants from unknown installers. Treat the leaked panel's 210 as a snapshot, not a live victim count.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free