CYBERRAKSHAK LABS Β· RESEARCH #029

🚨 Mantax Otax Android Malware: The Ransomware That Can Steal OTPs, Spy on WhatsApp and Control Your Phone

CyberRakshakLabs analysis of Mantax Otax, an Android malware family combining spyware, OTP theft, surveillance, remote control, ransomware and psychological harassment.

By Vivek Kumar Β· Published 12 September 2026
RESEARCH#029
CATEGORYAndroid Malware / Mobile Threat Intelligence
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-09-12
Source & social links:
LinkedIn Post β†—WhatsApp β†—YouTube β†—
How CyberRakshakLabs researches threats β†’
This is not just mobile ransomware.
Mantax Otax combines surveillance, OTP theft, remote control, ransomware and psychological harassment into one Android attack chain.
OTPSMS & notification theft
2Malware versions identified
Android 9Older versions face greater ransomware impact
HIGHCyberRakshakLabs assessment

1. Executive Summary

Zimperium's zLabs research describes Mantax Otax as an Android malware family linked to Indonesian threat actors, with analysed samples indicating targeting of Indonesian users. The samples combine ransomware with spyware and remote-control capabilities, including SMS/OTP theft, WhatsApp and Telegram surveillance, screen capture, camera access, location tracking, lock-screen PIN theft, file encryption and harassment.

The malware is distributed through malicious APKs outside Google Play and relies on phishing, shared links and social engineering to convince users to sideload the application.

CyberRakshakLabs assessment: The dangerous part is the combination. The attacker can first observe and collect information, then use device control and ransomware to increase pressure on the victim.

2. What Is Mantax Otax?

Mantax Otax represents a hybrid mobile threat: Spyware + RAT-like remote control + Ransomware + Extortion. Zimperium identified two versions, with the newer variant adding WebSocket communication and more aggressive device-interference features such as screen blocking, touch blocking, dialog spam, full-screen overlays, jumpscares and remote text-to-speech.

3. How Does It Reach Victims?
Phishing / Social Engineering→Malicious APK→Sideload→Permissions→Accessibility→Compromise

Zimperium's analysed samples were hosted on third-party file-sharing infrastructure and were consistent with distribution through shared links, messaging platforms and phishing/social-engineering messages.

Red flag: An APK being sent by someone you know on WhatsApp or Telegram is not proof that it is safe.
4. Accessibility: The Permission That Changes the Risk

Accessibility is a legitimate Android capability, but a malicious application can abuse it to read what appears on screen, simulate interaction, click controls, navigate applications and extract information. Zimperium observed Mantax Otax using Accessibility-driven interactions to navigate apps and collect data.

CyberRakshakLabs rule: Never grant Accessibility access to an unknown APK simply because the application claims it is required for the app to work.
5. Command & Control

The malware communicates with attacker infrastructure over HTTPS and retrieves an active C2 domain through a GitHub repository. Zimperium documented apimantax[.]otax[.]fun in the analysed infrastructure, along with device registration data such as device ID, location, network operator and Android version. Firebase infrastructure and, in the newer version, WebSockets support command delivery.

IOC note: this indicator comes from the referenced research and should be validated through your organisation's threat-intelligence workflow before operational blocking.

6. OTP Theft Changes the MFA Equation

Mantax Otax can monitor notifications and SMS messages and extract one-time passwords. That potentially exposes banking OTPs, verification codes, password-reset codes and authentication messages.

Password+OTP→Normal MFA
Password+Malware steals OTP→Compromised device

Mobile security is therefore part of identity security. Protecting the account while ignoring the device receiving the authentication code leaves a major attack surface exposed.

7. WhatsApp, Telegram & Private Conversations

WhatsApp

Profile information, messages and contact-related content can be extracted through Accessibility-driven interaction.

Telegram

Credentials and chat-history information can be targeted through the malware's application-navigation capabilities.

This can expose personal conversations, work discussions, photos, shared documents, authentication information and contact relationships.

8. Screen Monitoring & Camera Surveillance

Mantax Otax abuses Android's MediaProjection functionality for screenshots, screen recording and screen streaming. Zimperium also observed captured screen content being staged on Catbox before links were returned to attacker infrastructure. The malware can also remotely activate front or rear cameras and transmit captured images.

Why this matters: An attacker may not need to break into a banking application if they can watch the screen while the victim uses it.

9. Lock-Screen PIN Theft & Device Control

The malware can present overlays that imitate legitimate system processes and attempt to capture the device's lock-screen PIN. This can provide another route to device access and persistence.

10. The Ransomware Component

Mantax Otax obtains a victim-specific AES key from its C2, scans accessible storage, encrypts targeted files, deletes originals and creates .enc files. The ransomware impact is significantly greater on Android 9 and earlier devices because Android 10 introduced Scoped Storage restrictions that constrain access to shared storage.

Important: Android 10+ users are not β€œsafe.” Scoped Storage limits the ransomware blast radius, but the spyware, credential theft, surveillance and remote-control capabilities remain serious risks.

11. Mantax Otax v2: Psychological Warfare

πŸŸ₯ Screen blocking
πŸŸ₯ Touch blocking
πŸŸ₯ Dialog spamming
πŸŸ₯ Full-screen video overlays
πŸŸ₯ Jumpscare images
πŸŸ₯ Remote text-to-speech

The second version turns technical control into psychological pressure. Zimperium documented remote UI disruption designed to interfere with normal device use and intimidate the victim.

12. The Full Mantax Otax Attack Chain
01

Social Engineering

Phishing or malicious APK link.

02

Sideloading

Victim installs an APK outside trusted channels.

03

Permission Abuse

SMS, media, contacts and Accessibility access.

04

Device Registration

Device information is sent to C2.

05

Surveillance

SMS, OTP, messaging, location and device activity.

06

Credential Theft

GUI information and lock-screen PIN targeting.

07

Remote Monitoring

Screen capture, recording and camera access.

08

Data Collection

Files, media and personal information.

09

Ransomware

Accessible files are encrypted.

10

Harassment

Blocking, pop-ups, overlays and TTS.

11

Extortion

Victim communication and ransom pressure.

13. Why OTP Theft Is Particularly Dangerous

For a compromised phone, the authentication sequence can change from Password β†’ OTP β†’ Access to Password β†’ malware intercepts OTP β†’ attacker. This is why organisations should treat mobile-device compromise as an identity-security incident, not merely an endpoint problem.

14. What Android Users Should Do
🚫 Don't install random APKs from WhatsApp, Telegram, SMS, email or unknown websites.
πŸ” Treat Accessibility permission as high risk for unknown apps.
πŸ›‘οΈ Keep Android and security updates current.
🟒 Keep Google Play Protect enabled.
πŸ”Ž Regularly review SMS, Accessibility, notification, camera, microphone, location and storage permissions.
πŸ“± Avoid banking or password-reset activity on a potentially compromised phone.

Zimperium notes that the analysed ransomware functionality is substantially constrained on Android 10+ by Scoped Storage, while current reporting indicates up-to-date Android devices with active Play Protect can detect/block the identified malware.

15. If You Think Your Phone Is Infected
Disconnect→Stop Sensitive Activity→Use Trusted Device→Secure Accounts→Contact Bank→Preserve Evidence

Do not continue banking, using UPI or performing password resets from a potentially compromised phone. From another trusted device, change critical credentials, review active sessions and recovery methods, and contact your bank if banking information or OTPs may have been exposed. Preserve evidence before a factory reset or professional remediation where appropriate.

16. What Organisations Should Learn

BYOD becomes a serious identity and data-protection issue when personal Android devices access Microsoft 365, Google Workspace, VPNs, collaboration platforms, CRM systems, corporate email or banking systems. A compromised device can potentially expose credentials, OTPs, sessions and business communications.

Device Controls

MDM, Mobile Threat Defense, device-compliance checks, BYOD segmentation and mobile telemetry.

Identity Controls

Conditional Access, phishing-resistant authentication, app-protection policies and session/token revocation.

SOC Monitoring

Unknown APK installations, unexpected Accessibility use, new device administrators, suspicious permission changes and identity anomalies.

Response

Review sessions, credentials, MFA activity, application access and connections to suspicious C2 infrastructure.

17. MITRE ATT&CK Perspective

Zimperium mapped Mantax Otax to multiple mobile ATT&CK techniques, including phishing, input injection, abuse of Accessibility features, GUI input capture, notification access, location tracking, software/system discovery, screen capture, SMS collection and exfiltration over C2. The exact mapping should be tied to telemetry confirmed in an investigation.

18. Threat Intelligence Indicators

Observed C2 indicator: apimantax[.]otax[.]fun

Zimperium also documents GitHub-based dynamic C2 resolution and Firebase/WebSocket communications. Validate indicators through your own TI workflow before blocking or attributing activity.
19. CyberRakshakLabs Threat Assessment

Threat Type

Android Malware / Spyware / Ransomware

Initial Access

Phishing + malicious APK sideloading

Primary Abuse

Accessibility services and device permissions

Data Theft

SMS, OTP, contacts, call logs, location, browser history, messaging data, files and media

Surveillance

Screen capture, screen recording and camera access

Impact

File encryption, device disruption and psychological harassment

Threat Level: πŸ”΄ HIGH
Risk is especially serious for users who install APKs outside trusted stores, casually grant Accessibility access, use older Android versions, conduct banking on potentially compromised devices, reuse credentials or rely heavily on SMS OTP.

20. The Bigger Lesson

The Android phone is no longer just a communication device. It is a banking device, identity device, MFA receiver, private messaging platform, camera, document store and location tracker.

β€œIt’s only an APK” can be the wrong assumption. An APK can become the doorway to your OTPs, WhatsApp, files, screen, camera, accounts β€” and potentially your money.

Mantax Otax demonstrates the danger of combining surveillance, credential theft, remote control and ransomware in one mobile attack chain.

21. Final CyberRakshakLabs Takeaway

Don't install first and investigate later.
Investigate first β€” then install.

Think Before You Click. Stay Aware. Stay Secure.

Primary technical source: Zimperium zLabs β€” Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration. Published 9 September 2026.