MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign

 

MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to both lock users out of their devices and harvest sensitive personal data. Discovered by Zimperium's zLabs team and detailed in a September 9 technical write-up, the threat appears linked to Indonesian actors and spreads primarily via sideloaded APKs hosted on third-party file-sharing platforms. This dual-function design marks a significant escalation in mobile threats, combining financial extortion with deep surveillance to maximize victim impact. 
Once installed, MantaxOtax requests device administrator privileges, followed by permissions for SMS, contacts, audio, images, and Android Accessibility services, which grant it deep control over user interactions. It dynamically resolves its command-and-control (C2) domain from a GitHub repository, allowing operators to shift infrastructure without modifying the malware code. 
On Android 9 and earlier, it recursively scans external storage, encrypts files using AES with unique per-device keys fetched from C2, deletes originals, and leaves behind .enc files; on Android 10+, Scoped Storage limits encryption to the app's own directory. The malware also overwrites victims' images with ransom notes and opens a Firebase-based chat interface for extortion negotiations, which researchers found partially exposed due to a server misconfiguration. 
Beyond encryption, MantaxOtax operates as a full-featured spyware, collecting app inventories, hardware specs, location, browser history, notifications, contacts, call logs, and SMS—including one-time passwords (OTPs). It exfiltrates gallery content, linked Google accounts, WhatsApp profiles and messages (via Accessibility), and Telegram credentials and chat histories. By abusing Android's MediaProjection API, it captures screenshots, records MP4 screen videos, and streams near-real-time footage to attackers, storing media on the Catbox file host. It can also silently activate front or rear cameras to take photos without user knowledge, turning infected devices into always-on surveillance tools. 
Researchers observed multiple variants employing psychological pressure tactics: persistent screen locks, application blocking, and transparent overlays that hijack all touch input. Some versions bombard victims with repeating alert dialogs, full-screen video overlays, and image popups appearing every 600 milliseconds, while others use text-to-speech to audibly deliver attacker messages. A second iteration adopted WebSocket communications for more resilient C2 channels and added features like continuous screen locking and app blacklisting, making remediation harder for average users. These harassment techniques are designed to overwhelm victims into compliance, increasing the likelihood of ransom payment or credential surrender. 
Evidence including language markers and recovered victim files suggests MantaxOtax primarily targets Indonesian users. The misconfigured server also leaked what appears to be the operators' control panel, offering rare insight into their infrastructure. This campaign follows closely after the discovery of THost9, another Android trojan that clones banking apps into isolated work profiles to evade detection. Together, these threats underscore a growing trend of multi-stage mobile malware combining financial fraud, surveillance, and ransomware—highlighting the critical need for users to avoid sideloading apps, keep devices updated with the latest security patches, and use reputable mobile security solutions to detect and block such sophisticated threats before they cause harm.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: