// 2 CRITICAL · 7 ZERO-DAY · 16 CVE · 14 EXPLOIT · 2 ADVISORY IN THE LAST 24H
Zimperium zLabs discovered MantaxOtax, a hybrid Android malware combining AES ransomware with full-spectrum spyware, remote device control, and double-extortion tactics.

Zimperium zLabs discovered and documented MantaxOtax, a hybrid Android malware that combines AES ransomware capabilities with advanced spyware, remote device control, and double-extortion tactics. The discovery was published on September 9, 2026. The malware spreads exclusively via sideloading from third-party file-sharing platforms, requires device admin, SMS, contacts, audio, images, and Accessibility permissions, and is attributed to Indonesian threat actors based on linguistic indicators and recovered victim files.

Key Takeaways
  • The malware fuses AES ransomware (effective on Android 9 and earlier) with multi-channel spyware, remote control, and a psychological harassment system
  • The spyware component abuses the Accessibility API, MediaProjection API, and PIN injection to extract data from WhatsApp, Telegram, and capture screenshots, screen recordings, and near-real-time streaming
  • \li>Dynamic C2 domain resolution occurs via GitHub repositories, with a dual Firebase/WebSocket channel in version 2
  • A Firebase server misconfiguration exposed extortion chats and operator control-panel screenshots

How the Hybrid Architecture Works: Encryption Plus Total Surveillance

On Android 9 and earlier, MantaxOtax encrypts files with AES using a key derived from the C2 against the device's Android ID. The key is unique per victim, eliminating any possibility of offline or shared decryption. Original files are deleted and the .enc extension is appended to compromised documents. On Android 10 and later, Scoped Storage drastically limits the ransomware's impact: encryption is reduced to the app's external directory only, making the extortion module less effective on newer devices.

The spyware component operates independently of Android version. It collects app inventory, hardware details, geolocation, browser history, notifications, contacts, call logs, SMS including OTPs, gallery contents, and linked Google accounts. It extracts WhatsApp profiles and messages by abusing Accessibility APIs, along with Telegram credentials and chat history. Screen-unlock PIN access occurs via masquerading as a system lock process.

Visual and audiovisual capture capabilities are particularly aggressive. The malware abuses the MediaProjection API for screenshots, MP4 screen recording, and near-real-time streaming to Catbox, with links relayed to operators. It can also silently take photos using both device cameras.

Resilient C2 and the Flaw That Exposed Operators

The command-and-control infrastructure relies on dynamic C2 domain resolution from GitHub repositories. This technique lets operators swap infrastructure without modifying the APK code, ensuring resilience against takedowns. In version 2, the malware adds a WebSocket channel alongside Firebase for extortion chat.

A Firebase server misconfiguration exposed extortion chat logs and operator control-panel screenshots. The dossier does not specify whether this exposure led to nominal identification of the operators or if the configuration was subsequently corrected.

The Harassment Module: When Extortion Becomes Continuous Psychological Control

Version 2 introduces an arsenal of functions geared toward persistent psychological pressure. The malware implements persistent screen lock, specific app blocking, a transparent overlay that intercepts all user touches, repeated alert dialogs, full-screen video overlays, and image popups generated every 600 milliseconds. Remote text-to-speech allows operators to send voice messages directly to the victim's device.

These tactics shift the economic model from a one-time encryption event to an ongoing control experience. Double extortion materializes as payment to decrypt files and payment to prevent publication of exfiltrated data, with the added threat of real-time surveillance and contact with people in the victim's address book.

"Mantax Otax shows how mobile ransomware is evolving beyond file encryption into a broader device-compromise and extortion model" — Vishnu Pratapagiri, mobile security researcher at Zimperium zLabs

What to Do Now

For Android users, the primary protection is avoiding sideloading from third-party file-sharing platforms. The malware is not distributed through the Google Play Store. Verify that device admin, Accessibility, SMS, and audio permissions are not granted to apps of unknown origin.

For organizations with BYOD employees, the case highlights the limits of defenses based solely on official stores when personal devices access corporate data. A compromised device exposes 2FA OTPs and communications on platforms like WhatsApp and Telegram.

Zimperium MTD and zDefend detect samples via on-device dynamic detection, according to the cited source. Mapped MITRE ATT&CK techniques include: T1660 Phishing, T1655.001 Masquerading, T1516 Input Injection, T1453 Abuse Accessibility, T1417.002 GUI Input Capture, T1517 Access Notifications, T1430 Location Tracking, T1418 Software Discovery, T1426 System Information Discovery, T1513 Screen Capture, T1429 Audio Capture, T1616 Call Control, T1636.004 SMS Messages, T1646 Exfiltration Over C2, T1582 SMS Control.

Frequently Asked Questions

What is the difference between version 1 and version 2?

Version 2 adds the WebSocket channel for command and control, persistent screen lock, app blocking, transparent overlay with touch interception, image popups every 600 milliseconds, and remote text-to-speech for active psychological pressure.

Is the ransomware effective on all Android versions?

No. On Android 10 and later, Scoped Storage drastically limits encryption to the app's external directory only, reducing the ransomware module's impact. The spyware component remains operational regardless of version.

How to protect against MantaxOtax?

The dossier does not specify detailed preventive measures. The source indicates the malware spreads exclusively via sideloading from third-party file-sharing platforms, not through the Google Play Store.

The convergence of total surveillance, psychological extortion, and remote control signals a shift in the mobile threat landscape: the device is no longer just a container to be locked, but a sensory organ to be colonized. MantaxOtax operators have built a system where the victim pays not only to recover their files, but to stop an intrusion that continues to see, hear, and speak through their own phone.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. infosecurity-magazine.com
  2. radar.offseq.com
  3. undernews.fr
  4. securityinformed.com
  5. hendryadrian.com