Zimperium Uncovers Mantax Otax Android Malware That Encrypts Android 9 Files and Steals OTPs
Updated
Updated · eSecurity Planet · Sep 14
Zimperium Uncovers Mantax Otax Android Malware That Encrypts Android 9 Files and Steals OTPs
1 articles · Updated · eSecurity Planet · Sep 14
Summary
Mantax Otax can pair ransomware with spyware on one infected Android device, encrypting files on Android 9 or earlier while also harvesting SMS one-time passwords, chats, screens, photos and location data.
Malicious APKs distributed outside Google Play appear to be the main entry point, with phishing and social engineering used to win device administrator, Accessibility and other high-risk permissions.
GitHub-hosted command-and-control addresses let the malware register each phone and receive instructions to raid contacts, call logs, browser history and media, while abusing MediaProjection and the camera for live surveillance.
A misconfigured Firebase server showed the extortion flow after encryption: victims were pushed into an on-screen chat for ransom talks, and newer samples added intrusive dialogs, touch blocking and fake lock screens to pressure payment.
Android 10's scoped storage sharply limits the malware's file-encryption reach, but newer devices still face credential theft, app abuse and screen-blocking risks; Zimperium linked the observed operation to Indonesian threat actors.