Android Ransomware Records Screens, Steals OTPs, and Takes Photos
Key Takeaways A new Android malware, dubbed Mantax Otax, combines ransomware and spyware capabilities, targeting users who install apps from unofficial sources. The malware can encrypt user files,...
Key Takeaways
- A new Android malware, dubbed Mantax Otax, combines ransomware and spyware capabilities, targeting users who install apps from unofficial sources.
- The malware can encrypt user files, record screen activity, intercept One-Time Passwords (OTPs), and covertly capture photos using the device’s cameras.
- Researchers link the campaign to Indonesian threat actors, with evidence suggesting a focus on Indonesian victims.
- Mantax Otax leverages Android’s Accessibility Services and MediaProjection API for extensive surveillance and data exfiltration.
- Users are strongly advised to only download apps from official app stores and to be vigilant about requested permissions.
A sophisticated new Android threat has emerged, integrating both ransomware and spyware functionalities to ensnare users downloading applications from unofficial channels. This dual-threat malware, identified as Mantax Otax, presents a severe risk, transforming a single infection into a multifaceted crisis of extortion and privacy compromise.
Table Of Content
Mantax Otax possesses the capability to encrypt user files, monitor screen activity, intercept critical verification codes, and secretly activate a device’s cameras. This combination allows threat actors to not only hold data hostage but also to engage in extensive surveillance and potential account takeover, as detailed in a report shared with Cyber Security News (CSN).
The attack vector typically involves standalone Android Application Packages (APKs) hosted on various third-party file-sharing platforms. Users are often lured into downloading these malicious apps through deceptive links, messaging apps, or phishing campaigns, bypassing the security measures of official app stores.
Analysis of the malware, including language indicators and victim data, points to Indonesian threat actors and a primary focus on targets within Indonesia. This discovery underscores a growing trend where mobile cybercriminals are integrating surveillance, account theft, and file encryption into a single, potent package.
According to Zimperium, the repercussions of a Mantax Otax infection extend far beyond mere file loss. The theft of SMS-based one-time passwords (OTPs), chat histories, and even lock-screen PINs can provide attackers with sufficient information to compromise other online accounts or exert pressure on victims. This blend of capabilities mirrors other Android OTP theft campaigns, effectively transforming a compromised device into a tool for comprehensive account takeover.
Advanced Android Ransomware Capabilities
Upon successful installation, Mantax Otax initiates a series of permission requests, starting with device-administrator rights, then progressing to access SMS, contacts, audio, and images. Crucially, it seeks Accessibility Service access, a legitimate Android feature designed for user assistance but frequently abused by malware to read screen content and perform actions on behalf of the user. This particular permission abuse has been observed in other significant Android threats, such as the Crocodilus banking malware.
For devices running Android 9 or older, Mantax Otax aggressively targets external storage, encrypting images, videos, documents, and cryptographic keys using AES encryption. It then deletes the original files, appending a “.enc” extension to the encrypted versions. Furthermore, it overwrites existing images with a ransom note, demanding payment for file recovery. On Android 10 and newer versions, the impact of the ransomware component is somewhat mitigated due to Scoped Storage restrictions, which largely confine the app to its own external storage area. However, the surveillance capabilities remain unhindered.
After the encryption process, the malware can display an on-screen chat interface, enabling direct communication between the attackers and the victim to negotiate a ransom. This feature facilitates a “double extortion” scenario, where victims face both data encryption and the threat of leaked personal information.
Mantax Otax also exploits Android’s MediaProjection function, allowing it to capture screenshots, record the screen as MP4 video, and stream display content in near real-time. Captured screenshots are uploaded to services like Catbox, with their URLs then transmitted back to the attackers. This screen-viewing abuse is reminiscent of the recent StreamRAT mobile campaign, which allowed operators to remotely observe and manipulate infected devices.
Beyond screen monitoring, the spyware component can surreptitiously activate both front and rear cameras through a hidden preview surface, capturing photographs without any visible indication to the user. These images are compressed, stored locally, encoded, and then exfiltrated to the command-and-control server.
OTP Theft Elevates Account Compromise Risks
The malware systematically harvests a wide array of personal data, including contacts, call logs, browser history, location data, a list of installed applications, device information, linked Google account settings, and gallery files. It also actively monitors notifications and incoming SMS messages, directly compromising multi-factor authentication codes. Mantax Otax specifically targets WhatsApp profiles and messages, as well as Telegram credentials and chat histories, utilizing Accessibility Services to navigate and open conversations for data extraction.
To further facilitate credential theft, Mantax Otax employs a deceptive system-lock overlay. It presents itself as a critical system process, blocking normal device access and capturing any PIN entered by the victim. A more advanced second version of the malware incorporates WebSocket communications, app blocking mechanisms, a transparent overlay that intercepts touch input, disruptive pop-up messages, full-screen video overlays, and remote text-to-speech messages, significantly enhancing its intrusive capabilities.
The active command-and-control domain for Mantax Otax is dynamically retrieved from a GitHub repository, identified as hxxps://apimantax[.]otax[.]fun. (Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM).
What You Should Do
- Download from Official Sources: Always download apps exclusively from trusted platforms like the Google Play Store. Avoid sideloading APKs from unsolicited messages, social media posts, or unfamiliar file-sharing links.
- Review App Permissions: Scrutinize all permission requests from applications. If an app requests permissions like Accessibility Services, device administrator rights, SMS access, screen capture, or camera access that do not align with its stated functionality, deny them.
- Be Wary of Lock Screens and Overlays: If you encounter an unfamiliar lock screen, persistent overlay, or unexpected prompts for PINs or passwords, immediately disconnect your device from all networks (Wi-Fi and cellular) and seek professional cybersecurity assistance before entering any credentials.
- Enable Multi-Factor Authentication (MFA): Where possible, utilize stronger forms of MFA that do not rely solely on SMS, such as authenticator apps or hardware security keys.
- Regularly Back Up Data: Maintain regular backups of important data to cloud services or external storage, which can help mitigate the impact of ransomware attacks.
- For Organizations: Implement mobile device management (MDM) solutions to monitor for sideloaded applications, unusual Accessibility Service activations, screen-capture requests, and suspicious outbound network traffic on managed devices. Educate employees on the risks of unofficial app downloads and permission granting.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.