Mantax Otax combines surveillance, OTP theft, remote control, ransomware and psychological harassment into one Android attack chain.
1. Executive Summary
Zimperium's zLabs research describes Mantax Otax as an Android malware family linked to Indonesian threat actors, with analysed samples indicating targeting of Indonesian users. The samples combine ransomware with spyware and remote-control capabilities, including SMS/OTP theft, WhatsApp and Telegram surveillance, screen capture, camera access, location tracking, lock-screen PIN theft, file encryption and harassment.
The malware is distributed through malicious APKs outside Google Play and relies on phishing, shared links and social engineering to convince users to sideload the application.
2. What Is Mantax Otax?
Mantax Otax represents a hybrid mobile threat: Spyware + RAT-like remote control + Ransomware + Extortion. Zimperium identified two versions, with the newer variant adding WebSocket communication and more aggressive device-interference features such as screen blocking, touch blocking, dialog spam, full-screen overlays, jumpscares and remote text-to-speech.
3. How Does It Reach Victims?
Zimperium's analysed samples were hosted on third-party file-sharing infrastructure and were consistent with distribution through shared links, messaging platforms and phishing/social-engineering messages.
4. Accessibility: The Permission That Changes the Risk
Accessibility is a legitimate Android capability, but a malicious application can abuse it to read what appears on screen, simulate interaction, click controls, navigate applications and extract information. Zimperium observed Mantax Otax using Accessibility-driven interactions to navigate apps and collect data.
5. Command & Control
The malware communicates with attacker infrastructure over HTTPS and retrieves an active C2 domain through a GitHub repository. Zimperium documented apimantax[.]otax[.]fun in the analysed infrastructure, along with device registration data such as device ID, location, network operator and Android version. Firebase infrastructure and, in the newer version, WebSockets support command delivery.
IOC note: this indicator comes from the referenced research and should be validated through your organisation's threat-intelligence workflow before operational blocking.
6. OTP Theft Changes the MFA Equation
Mantax Otax can monitor notifications and SMS messages and extract one-time passwords. That potentially exposes banking OTPs, verification codes, password-reset codes and authentication messages.
Mobile security is therefore part of identity security. Protecting the account while ignoring the device receiving the authentication code leaves a major attack surface exposed.
7. WhatsApp, Telegram & Private Conversations
Profile information, messages and contact-related content can be extracted through Accessibility-driven interaction.
Telegram
Credentials and chat-history information can be targeted through the malware's application-navigation capabilities.
This can expose personal conversations, work discussions, photos, shared documents, authentication information and contact relationships.
8. Screen Monitoring & Camera Surveillance
Mantax Otax abuses Android's MediaProjection functionality for screenshots, screen recording and screen streaming. Zimperium also observed captured screen content being staged on Catbox before links were returned to attacker infrastructure. The malware can also remotely activate front or rear cameras and transmit captured images.
9. Lock-Screen PIN Theft & Device Control
The malware can present overlays that imitate legitimate system processes and attempt to capture the device's lock-screen PIN. This can provide another route to device access and persistence.
10. The Ransomware Component
Mantax Otax obtains a victim-specific AES key from its C2, scans accessible storage, encrypts targeted files, deletes originals and creates .enc files. The ransomware impact is significantly greater on Android 9 and earlier devices because Android 10 introduced Scoped Storage restrictions that constrain access to shared storage.
11. Mantax Otax v2: Psychological Warfare
The second version turns technical control into psychological pressure. Zimperium documented remote UI disruption designed to interfere with normal device use and intimidate the victim.
12. The Full Mantax Otax Attack Chain
Social Engineering
Phishing or malicious APK link.
Sideloading
Victim installs an APK outside trusted channels.
Permission Abuse
SMS, media, contacts and Accessibility access.
Device Registration
Device information is sent to C2.
Surveillance
SMS, OTP, messaging, location and device activity.
Credential Theft
GUI information and lock-screen PIN targeting.
Remote Monitoring
Screen capture, recording and camera access.
Data Collection
Files, media and personal information.
Ransomware
Accessible files are encrypted.
Harassment
Blocking, pop-ups, overlays and TTS.
Extortion
Victim communication and ransom pressure.
13. Why OTP Theft Is Particularly Dangerous
For a compromised phone, the authentication sequence can change from Password β OTP β Access to Password β malware intercepts OTP β attacker. This is why organisations should treat mobile-device compromise as an identity-security incident, not merely an endpoint problem.
14. What Android Users Should Do
Zimperium notes that the analysed ransomware functionality is substantially constrained on Android 10+ by Scoped Storage, while current reporting indicates up-to-date Android devices with active Play Protect can detect/block the identified malware.
15. If You Think Your Phone Is Infected
Do not continue banking, using UPI or performing password resets from a potentially compromised phone. From another trusted device, change critical credentials, review active sessions and recovery methods, and contact your bank if banking information or OTPs may have been exposed. Preserve evidence before a factory reset or professional remediation where appropriate.
16. What Organisations Should Learn
BYOD becomes a serious identity and data-protection issue when personal Android devices access Microsoft 365, Google Workspace, VPNs, collaboration platforms, CRM systems, corporate email or banking systems. A compromised device can potentially expose credentials, OTPs, sessions and business communications.
Device Controls
MDM, Mobile Threat Defense, device-compliance checks, BYOD segmentation and mobile telemetry.
Identity Controls
Conditional Access, phishing-resistant authentication, app-protection policies and session/token revocation.
SOC Monitoring
Unknown APK installations, unexpected Accessibility use, new device administrators, suspicious permission changes and identity anomalies.
Response
Review sessions, credentials, MFA activity, application access and connections to suspicious C2 infrastructure.
17. MITRE ATT&CK Perspective
Zimperium mapped Mantax Otax to multiple mobile ATT&CK techniques, including phishing, input injection, abuse of Accessibility features, GUI input capture, notification access, location tracking, software/system discovery, screen capture, SMS collection and exfiltration over C2. The exact mapping should be tied to telemetry confirmed in an investigation.
18. Threat Intelligence Indicators
apimantax[.]otax[.]funZimperium also documents GitHub-based dynamic C2 resolution and Firebase/WebSocket communications. Validate indicators through your own TI workflow before blocking or attributing activity.
19. CyberRakshakLabs Threat Assessment
Threat Type
Android Malware / Spyware / Ransomware
Initial Access
Phishing + malicious APK sideloading
Primary Abuse
Accessibility services and device permissions
Data Theft
SMS, OTP, contacts, call logs, location, browser history, messaging data, files and media
Surveillance
Screen capture, screen recording and camera access
Impact
File encryption, device disruption and psychological harassment
Risk is especially serious for users who install APKs outside trusted stores, casually grant Accessibility access, use older Android versions, conduct banking on potentially compromised devices, reuse credentials or rely heavily on SMS OTP.
20. The Bigger Lesson
The Android phone is no longer just a communication device. It is a banking device, identity device, MFA receiver, private messaging platform, camera, document store and location tracker.
Mantax Otax demonstrates the danger of combining surveillance, credential theft, remote control and ransomware in one mobile attack chain.
21. Final CyberRakshakLabs Takeaway
Investigate first β then install.
Think Before You Click. Stay Aware. Stay Secure.