Hybrid Mantax Otax Malware Merges Ransomware and Spyware on Android
A new strain linked to Indonesian actors combines data theft with file encryption and psychological harassment to overwhelm victims.
A new hybrid Android malware strain known as Mantax Otax has emerged, combining aggressive ransomware capabilities with advanced spyware to compromise mobile devices. Linked to Indonesian threat actors, the malware represents a tactical shift toward "loud" infections that simultaneously steal private data and lock users out of their files.
According to reports from Zimperium and BleepingComputer, Mantax Otax integrates a comprehensive suite of espionage tools. The malware is capable of harvesting contacts, call logs, and SMS messages, while also extracting browser histories and stealing lock screen PINs. Most notably, the strain can perform real-time screen recordings, allowing attackers to monitor user activity as it happens.
Beyond data theft, the malware employs targeted ransomware tactics. On devices running Android 9 or earlier, Mantax Otax performs a recursive scan of shared external storage and encrypts files using the AES encryption standard. This ensures that users on older operating systems lose access to their personal documents and media, creating a dual-threat scenario where the victim is both spied upon and extorted.
The Shift to Psychological Warfare
What distinguishes Mantax Otax from traditional mobile threats is its use of psychological harassment. Zimperium notes that the malware includes specific routines designed to degrade device usability through intensive UI disruption. These disruptions are not merely bugs but are intentional tactics used to harass the user and mask the malicious background tasks—such as data exfiltration—occurring in real time.
This hybrid approach significantly increases the severity of a mobile infection. By merging traditional ransomware with espionage tools, attackers can leverage stolen private data for blackmail or further exploitation even if the encryption demand is not met. The shift toward aggressive UI disruption marks a move away from stealthy persistence toward a strategy of overwhelming the user to prevent them from effectively intervening or securing the device.
Future Outlook
As mobile security evolves, the emergence of Mantax Otax highlights a growing trend of multi-functional malware that targets both the device's availability and the user's privacy. Security researchers continue to monitor the strain to determine if newer Android versions are vulnerable to similar UI-based harassment techniques or if the AES encryption routines will be updated to bypass current OS protections. For now, the primary risk remains concentrated on older Android versions and users susceptible to the initial infection vector.