Mantax Otax: New Android Malware Blends Ransomware, Spyware, and Harassment Tactics
A potent new Android malware strain, dubbed **Mantax Otax**, has emerged, combining the destructive capabilities of ransomware with the stealth of spyware and the psychological pressure of harassment. Indonesian threat actors are distributing this multifaceted malware through malicious APKs, targeting users outside the official Google Play ecosystem.
A new Android malware strain, **Mantax Otax**, has been identified, showcasing a concerning blend of ransomware, spyware, and harassment functionalities. This sophisticated threat is being propagated by Indonesian operators, primarily targeting users through malicious APKs hosted outside **Google Play** via phishing and social engineering tactics.
Upon successful installation, **Mantax Otax** aggressively requests **Accessibility service** permissions, granting it extensive control over the compromised device. It then establishes communication with its command-and-control (C2) infrastructure, often hosted on **GitHub**, to relay victim details such as location, carrier, Android version, and device ID. Commands are subsequently delivered via **Firebase** or **WebSockets**.
### Encrypting Older Android Devices
According to mobile security firm **Zimperium**, **Mantax Otax** specifically targets and encrypts devices running older Android versions. The malware scans shared storage for specific file types and encrypts them using a unique **AES** key obtained from the C2 server. Original files are deleted, and encrypted copies are appended with the `.enc` extension.
Furthermore, the malware replaces local images with ransom notices and opens a full-screen, **Firebase**-hosted chat interface to facilitate ransom payment negotiations.

**Zimperium** researchers ingeniously exploited a misconfiguration in the **Firebase** C2 server, enabling them to access the attackers' communications with victims.

It's important to note that **Mantax Otax**'s ransomware module is primarily effective against Android devices running version 9 or older. Android 10 and subsequent versions introduced the 'Scoped Storage' security feature, significantly restricting encryption capabilities to the external-files directory, thereby limiting the malware's impact on newer devices.
### Spyware, Remote Control, and Harassment Capabilities
Beyond ransomware, **Mantax Otax** boasts a robust suite of spyware, remote control, and harassment features. Researchers indicate the malware can steal lock-screen PINs to maintain persistent access, read SMS messages and one-time passwords, and access call logs, contacts, browsing history, app lists, **Google** account information, and location data.

It also demonstrates the ability to extract **WhatsApp** profiles and messages, as well as **Telegram** chats, by simulating user interactions via the **Accessibility services**. Leveraging Androidβs **MediaProjection API**, **Mantax Otax** can capture screenshots, record MP4 videos, and stream the victimβs screen in near real-time through the **Catbox** file hosting service. The malware can even capture photographs using the device's cameras and upload them to its operators.
Version 2 of **Mantax Otax** introduced aggressive harassment functions, including repeated dialog boxes, full-screen videos, rapid βjumpscareβ image overlays, and remotely controlled text-to-speech messages played through the device speakers. These features serve as a significant intimidation tactic, pressuring victims into paying the ransom.
As a **Google** security partner through the **App Defense Alliance (ADA)**, **Zimperium** has ensured that **Mantax Otax** is already detected and blocked by up-to-date Android devices with an active **Play Protect** service.
Users are strongly advised to avoid installing APKs from untrusted sources outside **Google Play**, to exercise extreme caution when granting **Accessibility permissions** to unfamiliar applications, and to only download apps from reputable publishers.