Advisory
Published 2026-09-15
Verified 2026-09-19

Mantax Otax: Indonesian Android ransomware + spyware (sideloaded APKs; Accessibility; GitHub C2)

Zimperium (blog; wired by BleepingComputer 15 September 2026) documents Mantax Otax, an Android strain combining ransomware, spyware, remote control, and harassment. Distributed as sideloaded APKs off Google Play via phishing/social engineering (Indonesian operators). After install it seeks Accessibility (and device-admin in analysed samples), resolves C2 from GitHub (domain cited as apimantax[.]otax[.]fun), registers device telemetry, and takes commands over Firebase/WebSockets. Ransomware module: victim-specific AES key from C2, encrypts shared-storage files on Android 9 and older (Scoped Storage limits impact on Android 10+), deletes originals, .enc extension, ransom UI via Firebase-hosted chat. Spyware: lock-screen PIN, SMS/OTP, calls, contacts, browsing history, Google account, location, WhatsApp/Telegram via Accessibility, MediaProjection screen capture/stream, camera stills. v2 adds jumpscare overlays and remote TTS harassment. Play Protect detects current samples via App Defense Alliance partnership. Primary: Zimperium; wire: BleepingComputer.

Product
Android (Mantax Otax malware; sideloaded APKs)
Versions
Ransomware encryption effective primarily on Android 9 and older; spyware/harassment broader
Exploited in Australia?
unknown
Patch to
Do not sideload APKs; deny Accessibility to untrusted apps; keep Play Protect on; wipe/restore if infected

Primary: Zimperium — Mantax Otax Indonesian mobile ransomware/spyware · Vendor: Zimperium research blog · BleepingComputer — Mantax Otax Android malware (15 Sep 2026)

tech