TechNewsReel
Live

Mantax Otax Android Malware Combines Spyware and Psychological Harassment

Indonesian-operated malware targets Android users with a 'cocktail' of data theft and jumpscares to force ransom payments.

TechNewsReel Newsroom · September 14, 2026

A sophisticated Android malware strain known as Mantax Otax is targeting users with a potent combination of ransomware and spyware capabilities. Operated by perpetrators based in Indonesia, the malware leverages social engineering to compromise devices and exert total control over victim data.

Distributed via malicious APKs through phishing campaigns, Mantax Otax bypasses the Google Play Store to infect targets. Once installed, the malware prompts users to grant it Accessibility service permissions, allowing attackers to automate device interactions and bypass security prompts. Security reports describe the malware as a "cocktail" of cybercrime, merging the traits of a Remote Access Trojan (RAT), an infostealer, and ransomware.

Technical Capabilities and Data Theft

The malware's surveillance capabilities are extensive. It can covertly take photos using the device camera, capture screenshots, and record MP4 videos via the MediaProjection API. Beyond visual spying, Mantax Otax exfiltrates a wide array of sensitive personal data, including lock-screen PINs, SMS messages, one-time passwords (OTPs), call logs, and contacts. It also scrapes browser history, Google account information, and private messages from WhatsApp and Telegram.

For users on legacy devices, the threat is more severe. On Android 9 and older, the malware encrypts shared storage using victim-specific AES keys, appending a ".enc" extension to affected files. To manage its operations, the malware retrieves its command-and-control (C2) domain from GitHub and maintains communication with the attackers via Firebase or WebSockets.

Psychological Warfare and Industry Impact

What distinguishes Mantax Otax from traditional ransomware is its use of psychological intimidation. Version 2 of the malware introduced harassment functions designed to pressure victims into paying ransoms. These include the deployment of rapid "jumpscare" image overlays and remotely controlled text-to-speech audio messages that play directly on the device.

This shift toward psychological warfare represents a growing trend in mobile malware, where attackers move beyond simple data encryption to active harassment. By combining the theft of intimate personal data with the ability to haunt the user's device in real-time, the operators increase the likelihood of a payout through fear and urgency.

The Path Forward

While the threat is significant, modern Android security architecture provides a critical defense. The ransomware module is largely ineffective on Android 10 and later due to the "Scoped Storage" security feature, which limits how apps can access the broader file system.

Security experts advise users to avoid installing APKs from untrusted sources and to be extremely cautious when apps request Accessibility service permissions. As the perpetrators refine their social engineering tactics, the industry will be watching to see if the Mantax Otax operators develop new methods to bypass the storage restrictions of newer Android versions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.