rootpwn

Threat Intel

Mantax Otax Malware Hybridizes Ransomware, Spyware, and Psychological Harassment on Android

Security researchers have uncovered Mantax Otax, an aggressive Android malware strain combining file encryption, data exfiltration, and psychological harassment techniques. Operating primarily through malicious side-loaded APKs, the threat abuses Accessibility services and GitHub to establish C2 connections, harvest sensitive user credentials, and lock files on older Android builds. Additionally, the malware deploys loud text-to-speech audio and jumpscare overlays to coerce victims into paying ransom demands.

Dual-Threat Android Attack Surface

A novel Android malware family dubbed Mantax Otax has emerged, blending conventional ransomware operations with invasive spyware and aggressive harassment tactics. Distributed through side-loaded Android application packages (APKs) outside the official Google Play store, the campaign leverages social engineering and phishing campaigns to lure victims into manually installing the compromised software.

Once installed, Mantax Otax requests elevated access to Android's Accessibility service. Securing this permission enables the malware to execute automated interface interactions, extract sensitive data, and secure persistence on the host device without requiring user intervention.

Infrastructure and Ransomware Mechanics

To establish its command-and-control (C2) link, the malware contacts a repository hosted on GitHub to retrieve its active command domain. It subsequently transmits telemetric data back to the attackers—including geographical coordinates, network carrier details, system build information, and unique hardware identifiers. Subsequent operational commands are processed via WebSockets or Firebase endpoints.

The ransomware module specifically targets devices running Android 9 or earlier versions. Due to security restrictions introduced in Android 10's Scoped Storage architecture, the malware's bulk file encryption capabilities are suppressed on modern OS builds. On vulnerable systems, it retrieves a victim-specific AES key from the C2 server, targets local files across shared storage directories, appends a customized extension, and overwrites existing media with static ransom notices while opening an embedded negotiation chat window.

Extensive Data Theft and Psychological Coercion

Beyond file encryption, Mantax Otax operates as a comprehensive spyware toolkit. The malware captures screen locks by deploying malicious login overlays, intercepts incoming SMS messages containing one-time passcodes, and extracts browser histories, contacts, call logs, and Google account details. Utilizing its Accessibility privileges, it actively scrapes messages and user profiles from encrypted messaging platforms such as WhatsApp and Telegram.

Furthermore, the threat abuses Android's MediaProjection API to capture screenshots and stream live device video to third-party file hosting infrastructure. Camera sensors can also be triggered remotely to capture photographs of the surrounding environment.

Recent iterations of the malware introduce psychological pressure tactics designed to compel ransom payments. Operators can remotely trigger rapid jumpscare image overlays, loop full-screen videos, trigger repetitive system alert prompts, and broadcast text-to-speech voice messages directly through the infected device's loudspeakers.

Android Malware Ransomware Spyware Mantax Otax Mobile Security

← All news