In a technical write up published on September 9, Zimperium's zLabs team linked the malware to Indonesian threat actors and said some samples appeared to have been distributed as a standalone Android package on a third‑party file‑sharing service.
How MantaxOtax combines file encryption with broad surveillance
Zimperium's analysis shows MantaxOtax is a hybrid: it performs conventional file‑encrypting ransomware actions while simultaneously operating as a full‑featured mobile spyware platform. The ransomware side scans and encrypts files, then presents an on‑screen negotiation chat. The spyware side collects app inventories, hardware details, location, browser history, notifications, contacts, call logs and SMS messages (including one‑time passwords), plus gallery content and linked Google accounts. It also harvests WhatsApp profiles and messages through Accessibility and pulls Telegram credentials and chat histories.
Technical controls abused: device administrator, Accessibility and MediaProjection
After installation MantaxOtax requests device administrator privileges, access to SMS, contacts, audio and images, and then Android Accessibility — the combination giving the malware broad control over device interactions. It abuses Android's MediaProjection API to capture screenshots, record MP4 screen videos, and stream near‑real‑time captures. Those captures are staged on the Catbox file host and links are sent back to operators. The malware can also take silent photos on either camera and intercept the lock screen PIN while masquerading as a system lock process.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleRansom tactics shift with Android platform protections
On Android 9 and earlier, MantaxOtax recursively scanned shared external storage and encrypted user files with AES, purging originals and leaving .enc copies. Each AES key is fetched from the command‑and‑control (C2) server keyed to the device's Android ID so no two victims share the same key. On Android 10 and later, Scoped Storage confined the scan to the app's own external files directory, sharply reducing what the malware could encrypt; to maintain pressure, Zimperium said MantaxOtax overwrote the victim's own image files with ransom graphics. An on‑screen chat interface opened for negotiation and those exchanges ran through Firebase — a misconfiguration of which left some extortion dialogues exposed.
Infrastructure and distribution: GitHub for C2 resolution, sideloading on third‑party services
Zimperium observed a technique that lets operators move infrastructure without changing malware code: the live C2 domain is resolved from a GitHub repository. That design lets operators switch to new infrastructure if a domain is blocked while keeping the same deployed binaries. Some samples appeared to be distributed as standalone Android packages on a third‑party file‑sharing service, pointing to sideloading as a propagation route. A misconfigured server also yielded a screenshot that appeared to be the operators' control panel.
Variants and nuisance behaviors: overlays, persistent locks, and audio harassment
Different MantaxOtax builds show divergent goals. A second version moved communications to WebSocket and added persistent screen locking, application blocking and a transparent overlay that swallows all touch input. Other builds appear designed to wear victims down rather than encrypt files: repeating alert dialogues, full‑screen video overlays, image popups spawning every 600 milliseconds, and text‑to‑speech that forces the handset to speak the attacker's words aloud. Zimperium also reported a routine that masquerades as a system lock process while intercepting the lock PIN.
What this means for security teams, end users, and enterprises
- Security teams and technologists: watch for malware that resolves C2 information from public GitHub content and for exposed Firebase backends. The mixed‑function nature of MantaxOtax — encryption limited by Android 10+ but extensive exfiltration via Accessibility and MediaProjection — means detection should include telemetry on Accessibility requests, MediaProjection use, device administrator grants, and unusual external uploads to hosts like Catbox.
- End users and the public: the samples Zimperium reviewed were distributed as standalone APKs on third‑party file‑sharing services, indicating sideloading remains a practical infection vector. Users should be cautious about installing packages outside official app stores and wary when apps request Accessibility, device administrator, or screen‑capture permissions.
- Enterprises and procurement leaders: MantaxOtax follows a recent trojan dubbed THost9 that used an isolated work profile to hide banking‑app fraud. Combined, these reports underline risks from apps that request broad Android privileges and from misconfigured backends (for example, Firebase) that can amplify operator control and expose victim dialogues or control‑panel screenshots.
MantaxOtax demonstrates a deliberate blending of two threat models: targeted surveillance and disruptive extortion. Zimperium's findings show operators prepared to adapt infrastructure via GitHub resolution and to exploit platform features — Accessibility and MediaProjection — to bypass limits that would otherwise blunt file‑encryption impact on newer Android releases. The misconfigurations Zimperium found — exposed extortion dialogues and an apparent control‑panel screenshot — also suggest operational mistakes that could provide defenders forensic leads as they hunt for victims and infrastructure.
Read the original Zimperium report: https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/




