Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Windows 11 Update KB5124008 Breaks Always-On VPN Connections
September 11, 2026
Android Ransomware Records Screens, Steals OTPs, and Takes Photos
September 11, 2026
Conti Ransomware Affiliate Sentenced for Attacks on 1,000+ Victims
September 11, 2026
Home/CyberSecurity News/Android Ransomware Records Screens, Steals OTPs, and Takes Photos
CyberSecurity News

Android Ransomware Records Screens, Steals OTPs, and Takes Photos

Key Takeaways A new Android malware, dubbed Mantax Otax, combines ransomware and spyware capabilities, targeting users who install apps from unofficial sources. The malware can encrypt user files,...

Jennifer sherman
Jennifer sherman
September 11, 2026 5 Min Read
3 0

Key Takeaways

  • A new Android malware, dubbed Mantax Otax, combines ransomware and spyware capabilities, targeting users who install apps from unofficial sources.
  • The malware can encrypt user files, record screen activity, intercept One-Time Passwords (OTPs), and covertly capture photos using the device’s cameras.
  • Researchers link the campaign to Indonesian threat actors, with evidence suggesting a focus on Indonesian victims.
  • Mantax Otax leverages Android’s Accessibility Services and MediaProjection API for extensive surveillance and data exfiltration.
  • Users are strongly advised to only download apps from official app stores and to be vigilant about requested permissions.

A sophisticated new Android threat has emerged, integrating both ransomware and spyware functionalities to ensnare users downloading applications from unofficial channels. This dual-threat malware, identified as Mantax Otax, presents a severe risk, transforming a single infection into a multifaceted crisis of extortion and privacy compromise.

Table Of Content

  • Key Takeaways
  • Advanced Android Ransomware Capabilities
  • OTP Theft Elevates Account Compromise Risks
  • What You Should Do

Mantax Otax possesses the capability to encrypt user files, monitor screen activity, intercept critical verification codes, and secretly activate a device’s cameras. This combination allows threat actors to not only hold data hostage but also to engage in extensive surveillance and potential account takeover, as detailed in a report shared with Cyber Security News (CSN).

The attack vector typically involves standalone Android Application Packages (APKs) hosted on various third-party file-sharing platforms. Users are often lured into downloading these malicious apps through deceptive links, messaging apps, or phishing campaigns, bypassing the security measures of official app stores.

Analysis of the malware, including language indicators and victim data, points to Indonesian threat actors and a primary focus on targets within Indonesia. This discovery underscores a growing trend where mobile cybercriminals are integrating surveillance, account theft, and file encryption into a single, potent package.

According to Zimperium, the repercussions of a Mantax Otax infection extend far beyond mere file loss. The theft of SMS-based one-time passwords (OTPs), chat histories, and even lock-screen PINs can provide attackers with sufficient information to compromise other online accounts or exert pressure on victims. This blend of capabilities mirrors other Android OTP theft campaigns, effectively transforming a compromised device into a tool for comprehensive account takeover.

Advanced Android Ransomware Capabilities

Upon successful installation, Mantax Otax initiates a series of permission requests, starting with device-administrator rights, then progressing to access SMS, contacts, audio, and images. Crucially, it seeks Accessibility Service access, a legitimate Android feature designed for user assistance but frequently abused by malware to read screen content and perform actions on behalf of the user. This particular permission abuse has been observed in other significant Android threats, such as the Crocodilus banking malware.

For devices running Android 9 or older, Mantax Otax aggressively targets external storage, encrypting images, videos, documents, and cryptographic keys using AES encryption. It then deletes the original files, appending a “.enc” extension to the encrypted versions. Furthermore, it overwrites existing images with a ransom note, demanding payment for file recovery. On Android 10 and newer versions, the impact of the ransomware component is somewhat mitigated due to Scoped Storage restrictions, which largely confine the app to its own external storage area. However, the surveillance capabilities remain unhindered.

After the encryption process, the malware can display an on-screen chat interface, enabling direct communication between the attackers and the victim to negotiate a ransom. This feature facilitates a “double extortion” scenario, where victims face both data encryption and the threat of leaked personal information.

Mantax Otax also exploits Android’s MediaProjection function, allowing it to capture screenshots, record the screen as MP4 video, and stream display content in near real-time. Captured screenshots are uploaded to services like Catbox, with their URLs then transmitted back to the attackers. This screen-viewing abuse is reminiscent of the recent StreamRAT mobile campaign, which allowed operators to remotely observe and manipulate infected devices.

Beyond screen monitoring, the spyware component can surreptitiously activate both front and rear cameras through a hidden preview surface, capturing photographs without any visible indication to the user. These images are compressed, stored locally, encoded, and then exfiltrated to the command-and-control server.

OTP Theft Elevates Account Compromise Risks

The malware systematically harvests a wide array of personal data, including contacts, call logs, browser history, location data, a list of installed applications, device information, linked Google account settings, and gallery files. It also actively monitors notifications and incoming SMS messages, directly compromising multi-factor authentication codes. Mantax Otax specifically targets WhatsApp profiles and messages, as well as Telegram credentials and chat histories, utilizing Accessibility Services to navigate and open conversations for data extraction.

To further facilitate credential theft, Mantax Otax employs a deceptive system-lock overlay. It presents itself as a critical system process, blocking normal device access and capturing any PIN entered by the victim. A more advanced second version of the malware incorporates WebSocket communications, app blocking mechanisms, a transparent overlay that intercepts touch input, disruptive pop-up messages, full-screen video overlays, and remote text-to-speech messages, significantly enhancing its intrusive capabilities.

The active command-and-control domain for Mantax Otax is dynamically retrieved from a GitHub repository, identified as hxxps://apimantax[.]otax[.]fun. (Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM).

What You Should Do

  • Download from Official Sources: Always download apps exclusively from trusted platforms like the Google Play Store. Avoid sideloading APKs from unsolicited messages, social media posts, or unfamiliar file-sharing links.
  • Review App Permissions: Scrutinize all permission requests from applications. If an app requests permissions like Accessibility Services, device administrator rights, SMS access, screen capture, or camera access that do not align with its stated functionality, deny them.
  • Be Wary of Lock Screens and Overlays: If you encounter an unfamiliar lock screen, persistent overlay, or unexpected prompts for PINs or passwords, immediately disconnect your device from all networks (Wi-Fi and cellular) and seek professional cybersecurity assistance before entering any credentials.
  • Enable Multi-Factor Authentication (MFA): Where possible, utilize stronger forms of MFA that do not rely solely on SMS, such as authenticator apps or hardware security keys.
  • Regularly Back Up Data: Maintain regular backups of important data to cloud services or external storage, which can help mitigate the impact of ransomware attacks.
  • For Organizations: Implement mobile device management (MDM) solutions to monitor for sideloaded applications, unusual Accessibility Service activations, screen-capture requests, and suspicious outbound network traffic on managed devices. Educate employees on the risks of unofficial app downloads and permission granting.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Conti Ransomware Affiliate Sentenced for Attacks on 1,000+ Victims

Next Post

Windows 11 Update KB5124008 Breaks Always-On VPN Connections

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
IDScan.net Confirms Breach After 153 Million Driver’s Licenses Leaked
September 11, 2026
Critical Ivanti EPMM CVE-2023-35078 Flaw Lets Attackers Access Devices
September 11, 2026
Okta Patches Critical Auth0 and Access Gateway Flaws
September 11, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us