Zimperium has spotted new Android malware that combines two rarely seen threats in the same package: ransomware and spyware. Is called Mantax Otaxcurrently only circulating in Indonesia, and after encrypting the victim’s files, it opens a chat window to negotiate the ransom in real time. Behind it are Indonesian operators who exploit phishing and social engineering to convince users to manually install an APK downloaded outside the Play Store.
The distribution passes through third-party file sharing services, not from the official store: victims receive links on messaging apps and are encouraged to complete sideloading by hand. Upon first launch, the app asks for a long series of permissions, including access to accessibility serviceswhich are effectively equivalent to administrator privileges on the device. That’s where everything is decided: whoever grants that permission gives the malware almost total control of the smartphone.
Once the connection is established with the command and control server, whose location is retrieved from a GitHub repository, Mantax Otax starts encrypting the files with the algorithm AESadds the extension .enc and delete the originals. According to Zimperium researchers, the operation is especially successful on older devices, where system protections are less stringent.
Not just a ransomware, but a spyware that watches live
The ransomware module works at full capacity only on Android 9 and previous versions. From Android 10 onwards, Scoped Storage limits access to shared storage, and the recursive scanning that the malware performs loses much of its effectiveness. The authors are aiming precisely at older devices, still very widespread in markets such as the Indonesian one.
Mantax Otax shows fake lock screen to intercept PIN, reads SMS and OTP codes, accesses contacts, call history, browsing history, installed apps list, Google account and GPS location. Thanks to simulated interactions through accessibility services, it is also able to extract conversations from WhatsApp And Telegram.
The surveillance module takes advantage of the MediaProjection API to capture screenshots in JPEG, record screen video and stream display content in real time through the Catbox hosting service. To complete the picture there are silent shots with the front and rear cameras, sent directly to the operators.
Version 2 of the malware added a psychological pressure component designed to pressure victims into paying: repeated dialog boxes, full-screen videos and “jumpscare” images overlaid every 600 millisecondsas well as voice messages synthesized and played remotely. Zimperium also managed to exploit a misconfiguration of the Firebase server used for extortion chats, a detail that allowed it to closely observe conversations between criminals and victims.
Zimperium is Google’s partner in the App Defense Alliance, so Mantax Otax is already recognized and blocked by PlayProtect on updated devices. The usual recommendation remains valid: Never install APKs downloaded outside the Play Store, never grant accessibility services to apps of uncertain origin. For now, the spread remains limited to Indonesia, but the combination of ransomware and spyware in a single package is a model that, if it works, tends to be replicated elsewhere.

