Advisory
Published 2026-09-09
Verified 2026-09-19

Mantax Otax: Indonesian Android ransomware plus spyware (Zimperium)

Zimperium zLabs (9 September 2026) describes Mantax Otax, an Android strain linked to Indonesian operators that combines spyware with ransomware. Samples were distributed as sideloaded APKs on third-party file hosts via phishing and social engineering, outside Google Play. After install it seeks device-admin and Accessibility permissions, pulls C2 from GitHub, and can use Firebase or WebSockets. Spyware capabilities reported include screen recording, browser history, lock-screen PIN theft, contacts, call logs, SMS, local file theft, and covert photos. On older Android versions it encrypts shared-storage files with a victim-specific AES key from C2, deletes originals, appends .enc, replaces images with ransom notices, and opens a full-screen Firebase-hosted chat for payment negotiation. Wire: BleepingComputer (10 Sep 2026). Primary: Zimperium blog.

Product
Android (Mantax Otax malware; sideloaded APK)
Versions
Encryption path reported against older Android versions; sideload infection model
Exploited in Australia?
unknown
Patch to
Block sideload; revoke Accessibility for untrusted apps; mobile Threat Defense / Play Protect; wipe if encrypted

Primary: Zimperium zLabs — Mantax Otax · Vendor: Zimperium (research) · BleepingComputer (10 Sep 2026)

tech identity