Threat reportMalwareTL-2026-2719
Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration
Mantax Otax: Indonesian Android Malware Combines Ransomware (TL-2026-2719), also tracked as Mantax OTAX, is a high-severity malware campaign, first published 2026-09-09. It has no confirmed attribution, affects Google Android OS, maps to 15 MITRE ATT&CK techniques (T1417.002, T1418, T1426), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2719
- Threat ID
- TL-2026-2719
- Also known as
- Mantax OTAX
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer
- Target regions
- indonesia, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Mantax Otax: Indonesian Android Malware Combines Ransomware
Malware and tooling: Mantax Otax
How Mantax Otax: Indonesian Android Malware Combines Ransomware works
Zimperium zLabs identified Mantax Otax, an Android malware family targeting Indonesian users that combines extensive spyware surveillance (screen recording, PIN theft, SMS/OTP interception, WhatsApp/Telegram theft, camera capture, location tracking) with ransomware capable of AES-encrypting files on Android 9 and earlier. It is sideloaded via phishing/social-engineering links and uses a GitHub-repo-based dynamic C2 resolution mechanism with Firebase and Catbox for exfiltration.
Mantax Otax is a hybrid Android malware family, documented by Zimperium zLabs on 2026-09-09, that fuses full-featured mobile spyware with a device-encrypting ransomware component and an active harassment/extortion-pressure layer. Two variants have been identified: a baseline v1 and a more advanced v2 that adds coercive UI-manipulation commands. The malware is distributed outside Google Play as standalone APKs hosted on third-party file-sharing infrastructure (MediaFire, and the actor's own otax.fun domain), pushed to victims through phishing messages, messaging-platform links, and social-engineering lures rather than any software vulnerability or exploit chain.
Once sideloaded, the app requests Device Administrator privileges and Android Accessibility Service access, which it abuses as the root enabler for nearly all of its capabilities. Using the Accessibility APIs it performs Input Injection to mimic user interaction (e.g., stealing lock-screen PINs via a device-locking overlay) and harvests WhatsApp message content/profile data and Telegram credentials and chat history directly from the UI. It abuses the Android MediaProjection API to perform real-time screen recording (encoded as MP4) and periodic screenshots (JPEG), streaming a near-real-time live view of the victim's display back to the operator as Base64-encoded frames. Additional collection includes SMS and one-time-password interception, silent front/rear camera capture without user interaction, physical location tracking, contact-list and call-log harvesting, browser history extraction, and notification-content monitoring — giving the operator both financial-fraud-grade credential access and full device surveillance.
On devices running Android 9 or earlier, Mantax Otax additionally functions as ransomware: it AES-encrypts media, documents, archives, databases, and cryptographic-key files, appends a '.enc' extension, and securely deletes the originals, then replaces local images with ransom notices and opens an interactive on-device chat portal for extortion negotiation. The encryption key used is victim-specific and is retrieved from the actor's C2 infrastructure rather than generated purely on-device. On Android 10 and later, native Scoped Storage restrictions confine this component to app-private directories, sharply limiting its practical impact — though the spyware and device-control functionality remain fully active regardless of OS version.
Mantax Otax's C2 model is designed to survive takedown of any single domain: the app resolves its active C2 endpoint dynamically by reading a value from a GitHub repository rather than hardcoding it, letting operators rotate infrastructure without shipping an app update. Confirmed backend domains/IPs include apimantax.otax.fun (also used to host APK payloads directly), apixnxx.otax.fun, nodemyayun.otax.store, and cromwell.danzzichosting.my.id, alongside raw C2 IP:port pairs 38.45.65.159:2034 and 96.9.212.22:2034. The v1 C2 channel runs over HTTPS; v2 upgrades to a persistent WebSocket connection. Firebase Realtime Database instances (otax-ceada-default-rtdb and mantax-e0919-default-rtdb, both in the asia-southeast1 region) serve as the backend for the ransom chat interface and command dispatch. Zimperium researchers were able to exploit a misconfiguration in this Firebase backend to directly observe attacker-victim communications and operational data. Captured screenshots and screen-recording video are exfiltrated to the third-party host Catbox rather than the primary C2, separating bulk-media exfiltration from the control channel. On first execution the malware registers a unique device_id against a '/register' endpoint together with geolocation, network operator, and OS version.
The v2 variant adds a set of remote commands purpose-built to pressure victims into paying rather than to expand technical capability: <blockapp> dynamically restricts access to a targeted application, <touchBlock> raises a transparent full-screen overlay that intercepts all touch input, <dialogSpam>/<dialogSpamStop> floods the screen with alert dialogs, <videoOverlay> obstructs the display with full-screen video, <jumpscarestart>/<jumpscare2Start> injects full-screen image popups at roughly 600ms intervals, and <TTS_SPEAK> uses the device's own text-to-speech engine to vocalize threat messages aloud. The attacker-facing control panel observed by researchers displayed a running count of infected devices, though the exact figure was not disclosed.
Attribution is inferred only from language indicators and artifacts recovered from victim devices pointing to Indonesian-origin operators targeting Indonesian victims; no named threat-actor group, group aliases, or nation-state sponsorship have been established, and Zimperium's reporting treats this as financially motivated cybercriminal activity rather than espionage. Google has confirmed Play Protect already detects and blocks known Mantax Otax samples, and Zimperium — a Google App Defense Alliance partner — published a corresponding IOC set (APK hashes, C2 infrastructure, phishing distribution URLs) to its public GitHub IOC repository at the time of disclosure.
MITRE ATT&CK techniques used in TL-2026-2719
Credential Access
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Collection
T1429 Audio Capture; T1430 Location Tracking; T1513 Screen Capture; T1517 Access Notifications; T1616 Call Control; T1636.004 SMS Messages
collection
T1453 Abuse Accessibility Features
Impact
T1516 Input Injection; T1582 SMS Control
Exfiltration
T1646 Exfiltration Over C2 Channel
Defense Evasion
T1655.001 Match Legitimate Name or Location
Initial Access
Affected products and versions in Mantax Otax: Indonesian Android Malware Combines Ransomware
- Google — Android OS
Vulnerable versions: Android 9 and earlier (full AES file-encryption/ransomware capability); all Android versions (spyware, credential-theft, and device-control functionality)
Fixed in: Android 10+ (Scoped Storage restricts the ransomware component to app-private directories; does not mitigate spyware/surveillance functions)
Remediation for Mantax Otax: Indonesian Android Malware Combines Ransomware
Patches
- No vendor patch applies — this is a malware family, not a software vulnerability; Android 10+ Scoped Storage is the relevant structural OS mitigation for the ransomware component only.
Immediate actions
- Do not sideload APKs received via phishing links, messaging-app shares, or third-party file-sharing sites (MediaFire, Catbox, otax.fun); install only from Google Play.
- Revoke Device Administrator and Accessibility Service permissions from any unrecognized or recently sideloaded application, and uninstall it.
- Block known Mantax Otax C2 infrastructure at DNS/perimeter: apimantax.otax.fun, apixnxx.otax.fun, nodemyayun.otax.store, cromwell.danzzichosting.my.id, and IPs 38.45.65.159 / 96.9.212.22.
- Confirm Google Play Protect is enabled and current; Google has confirmed it already detects and blocks known Mantax Otax samples.
Workarounds
- Maintain offline or cloud backups of media, documents, and databases to reduce impact from the AES file-encryption component.
- Disable 'install unknown apps' / unknown-sources installation in Android Settings to prevent sideloading of the distributed APKs.
Longer-term hardening
- Upgrade legacy handsets from Android 9 or earlier to Android 10+ so Scoped Storage structurally limits the ransomware component to app-private directories.
- Deploy mobile threat defense (MTD) tooling capable of flagging abuse of the MediaProjection API and Accessibility Service APIs by third-party apps.
- Run security-awareness campaigns targeting phishing and social-engineering lures delivered over messaging apps, which is Mantax Otax's sole observed infection vector.
Timeline of Mantax Otax: Indonesian Android Malware Combines Ransomware
- Security press outlets (BleepingComputer, Cyberpress, Security Journal Americas, Android Headlines, Rankiteo) republish and corroborate Zimperium's findings on the same disclosure.
- Google confirms Play Protect already detects and blocks known Mantax Otax samples; Zimperium is credited as a Google App Defense Alliance partner in the disclosure.
- Malpedia adds a library entry cataloguing Mantax Otax as a distinct tracked Android malware family.
- Zimperium publishes an IOC set — APK SHA-256 hashes, C2 domains/IPs, and phishing distribution URLs — to its public GitHub IOC repository under 2026-09-MantaxOtax.
- Researchers exploit a misconfiguration in the malware operator's Firebase Realtime Database backend, directly exposing attacker-victim ransom chat communications and operational data.
- Zimperium identifies two variants — a baseline v1 and a more advanced v2 that adds coercive full-screen harassment commands (blockapp, touchBlock, jumpscarestart, TTS_SPEAK) and moves the C2 channel to WebSockets.
- Zimperium zLabs publishes the initial technical analysis of Mantax Otax, an Indonesian Android malware family fusing ransomware and spyware capabilities.
Sources cited for Mantax Otax: Indonesian Android Malware Combines Ransomware
- Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
- Malpedia library entry: Mantax Otax
- Zimperium IOC Repository: 2026-09-MantaxOtax
- New Android malware encrypts files, steals data, and harasses victims
- Mantax OTAX Combines Android Ransomware and Spyware for Double-Extortion Attacks
- Zimperium zLabs Uncovers Mantax Otax Android Malware
- Mantax Otax Malware Can Encrypt, Spy On, and Harass Android Users
- Mantax OTAX: Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Detection coverage for TL-2026-2719
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2719 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.