# Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration

> Zimperium zLabs identified Mantax Otax, an Android malware family targeting Indonesian users that combines extensive spyware surveillance (screen recording, PIN theft, SMS/OTP interception, WhatsApp/Telegram theft, camera capture, location tracking) with ransomware capable of AES-encrypting files on Android 9 and earlier. It is sideloaded via phishing/social-engineering links and uses a GitHub-repo-based dynamic C2 resolution mechanism with Firebase and Catbox for exfiltration.

- **Published:** 2026-09-09T00:00:00Z
- **Last reviewed:** 2026-09-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2719
- **ID:** TL-2026-2719
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Mantax Otax is a hybrid Android malware family, documented by Zimperium zLabs on 2026-09-09, that fuses full-featured mobile spyware with a device-encrypting ransomware component and an active harassment/extortion-pressure layer. Two variants have been identified: a baseline v1 and a more advanced v2 that adds coercive UI-manipulation commands. The malware is distributed outside Google Play as standalone APKs hosted on third-party file-sharing infrastructure (MediaFire, and the actor's own otax.fun domain), pushed to victims through phishing messages, messaging-platform links, and social-engineering lures rather than any software vulnerability or exploit chain.

Once sideloaded, the app requests Device Administrator privileges and Android Accessibility Service access, which it abuses as the root enabler for nearly all of its capabilities. Using the Accessibility APIs it performs Input Injection to mimic user interaction (e.g., stealing lock-screen PINs via a device-locking overlay) and harvests WhatsApp message content/profile data and Telegram credentials and chat history directly from the UI. It abuses the Android MediaProjection API to perform real-time screen recording (encoded as MP4) and periodic screenshots (JPEG), streaming a near-real-time live view of the victim's display back to the operator as Base64-encoded frames. Additional collection includes SMS and one-time-password interception, silent front/rear camera capture without user interaction, physical location tracking, contact-list and call-log harvesting, browser history extraction, and notification-content monitoring — giving the operator both financial-fraud-grade credential access and full device surveillance.

On devices running Android 9 or earlier, Mantax Otax additionally functions as ransomware: it AES-encrypts media, documents, archives, databases, and cryptographic-key files, appends a '.enc' extension, and securely deletes the originals, then replaces local images with ransom notices and opens an interactive on-device chat portal for extortion negotiation. The encryption key used is victim-specific and is retrieved from the actor's C2 infrastructure rather than generated purely on-device. On Android 10 and later, native Scoped Storage restrictions confine this component to app-private directories, sharply limiting its practical impact — though the spyware and device-control functionality remain fully active regardless of OS version.

Mantax Otax's C2 model is designed to survive takedown of any single domain: the app resolves its active C2 endpoint dynamically by reading a value from a GitHub repository rather than hardcoding it, letting operators rotate infrastructure without shipping an app update. Confirmed backend domains/IPs include apimantax.otax.fun (also used to host APK payloads directly), apixnxx.otax.fun, nodemyayun.otax.store, and cromwell.danzzichosting.my.id, alongside raw C2 IP:port pairs 38.45.65.159:2034 and 96.9.212.22:2034. The v1 C2 channel runs over HTTPS; v2 upgrades to a persistent WebSocket connection. Firebase Realtime Database instances (otax-ceada-default-rtdb and mantax-e0919-default-rtdb, both in the asia-southeast1 region) serve as the backend for the ransom chat interface and command dispatch. Zimperium researchers were able to exploit a misconfiguration in this Firebase backend to directly observe attacker-victim communications and operational data. Captured screenshots and screen-recording video are exfiltrated to the third-party host Catbox rather than the primary C2, separating bulk-media exfiltration from the control channel. On first execution the malware registers a unique device_id against a '/register' endpoint together with geolocation, network operator, and OS version.

The v2 variant adds a set of remote commands purpose-built to pressure victims into paying rather than to expand technical capability: <blockapp> dynamically restricts access to a targeted application, <touchBlock> raises a transparent full-screen overlay that intercepts all touch input, <dialogSpam>/<dialogSpamStop> floods the screen with alert dialogs, <videoOverlay> obstructs the display with full-screen video, <jumpscarestart>/<jumpscare2Start> injects full-screen image popups at roughly 600ms intervals, and <TTS_SPEAK> uses the device's own text-to-speech engine to vocalize threat messages aloud. The attacker-facing control panel observed by researchers displayed a running count of infected devices, though the exact figure was not disclosed.

Attribution is inferred only from language indicators and artifacts recovered from victim devices pointing to Indonesian-origin operators targeting Indonesian victims; no named threat-actor group, group aliases, or nation-state sponsorship have been established, and Zimperium's reporting treats this as financially motivated cybercriminal activity rather than espionage. Google has confirmed Play Protect already detects and blocks known Mantax Otax samples, and Zimperium — a Google App Defense Alliance partner — published a corresponding IOC set (APK hashes, C2 infrastructure, phishing distribution URLs) to its public GitHub IOC repository at the time of disclosure.

## MITRE ATT&CK

- T1660 Phishing
- T1655.001 Match Legitimate Name or Location
- T1516 Input Injection
- T1453 Abuse Accessibility Features
- T1417.002 GUI Input Capture
- T1517 Access Notifications
- T1430 Location Tracking
- T1418 Software Discovery
- T1426 System Information Discovery
- T1513 Screen Capture
- T1429 Audio Capture
- T1636.004 SMS Messages
- T1616 Call Control
- T1646 Exfiltration Over C2 Channel
- T1582 SMS Control

## Sources

- [Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration](https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration)
- [Malpedia library entry: Mantax Otax](https://malpedia.caad.fkie.fraunhofer.de/library/417e8e0e-cf02-499a-9e51-b897b0877724/)
- [Zimperium IOC Repository: 2026-09-MantaxOtax](https://github.com/Zimperium/IOC/tree/master/2026-09-MantaxOtax/)
- [New Android malware encrypts files, steals data, and harasses victims](https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/)
- [Mantax OTAX Combines Android Ransomware and Spyware for Double-Extortion Attacks](https://cyberpress.org/mantax-otax-android-double-extortion/)
- [Zimperium zLabs Uncovers Mantax Otax Android Malware](https://securityjournalamericas.com/zimperium-zlabs-android-malware/)
- [Mantax Otax Malware Can Encrypt, Spy On, and Harass Android Users](https://www.androidheadlines.com/2026/09/mantax-otax-malware-encrypts-spies-harasses-android-users.html)
- [Mantax OTAX: Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files](https://blog.rankiteo.com/zim1789115173-mantax-otax-ransomware-september-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2719
