CampaignSMS

Mantax OTAX Combines Android Ransomware and Spyware for Double-Extortion Attacks – cyberpress.org

Linked to Indonesian threat actors, the malware represents a serious double-extortion risk it steals sensitive data before encrypting files and demands payment through a built-in chat feature.
The malware is distributed as a malicious Android APK hosted on third-party file-sharing services. Victims may be tricked into sideloading it through phishing messages, social-engineering lures, shared links, or messaging platforms. This delivery method helps operators bypass official app-store checks.
After installation, Mantax OTAX requests device administrator access and a wide range of dangerous permissions. These include access to SMS messages, contacts, audio, images, and Accessibility services.
If granted, the permissions give attackers extensive visibility and control over the infected device.
The malware communicates with its command-and-control server over HTTPS. It retrieves its active C2 address from a GitHub repository, allowing operators to change infrastructure quickly if a domain is blocked. One observed C2 domain was apimantax[.]otax[.]fun.
During device registration, Mantax OTAX sends the attacker a unique device ID, geographic location, network operator details, and Android version. It then receives commands through Firebase-backed infrastructure.
Mantax OTAX retrieves a unique encryption key from its C2 server and scans the device for valuable files.
It targets documents, images, videos, archives, databases, and cryptographic keys. On Android 9 and older versions, it can recursively encrypt much of the shared external storage using AES encryption.
Encrypted files receive the .enc extension, while the original files are deleted. The malware also replaces local images with ransom-note graphics stating: “Your files have been encrypted. Pay to decrypt.”
Android 10 and newer devices are less exposed to its ransomware routine because Scoped Storage limits the malware’s access to user files.
However, newer Android protections do not prevent its surveillance, credential theft, or screen-locking features when dangerous permissions have been granted.
The spyware component is extensive. Mantax OTAX can steal browser history, contacts, call logs, SMS messages, notification content, installed app lists, device information, Google account details, gallery media, and location data.
By monitoring notifications and SMS messages, it may also capture one-time passwords used for multi-factor authentication.
It can target WhatsApp and Telegram data through Accessibility abuse, simulating user interaction to collect chat content and account information.
The malware can also use Android’s MediaProjection API to take screenshots, record the screen, and stream display content in near real time.
Stolen screenshots and videos are uploaded to Catbox, while links are sent back to the attackers, Zimperium said.
Indicators of Compromise
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC

Exclusive Cyber Security News platform that provide in-depth analysis about Cyber Attacks, Malware infection, Data breaches, Vulnerabilities, New researches & other Cyber stories.
Contact Us: [email protected]
© Copyright 2026 – Cyber Press

source

Leave a Reply

Your email address will not be published. Required fields are marked *