Victim’s device before and after the ransomware attack | Image: zLabs
Security researchers recently uncovered the Mantax Otax Android malware. This dangerous Indonesian mobile ransomware integrates deep espionage capabilities with aggressive file encryption.
At a glance
- Malware family: Mantax Otax (and Mantax v2)
- Threat actor: Suspected Indonesian threat actors
- Target or victims: Android users (approx. 210 observed devices)
- Delivery vector: Sideloaded APKs via third-party sharing sites
- Key capabilities: AES encryption, screen recording, PIN theft, live chat extortion
- Source: Zimperium zLabs
TL;DR
The zLabs research team discovered the Mantax Otax Android malware. This mobile threat combines intrusive espionage tools with AES file encryption. Attackers use this hybrid tool to spy on victims, lock their screens, and demand ransoms via live chat.
Delivery
Threat actors distribute this Indonesian mobile ransomware using standalone Android application packages. They host these malicious files on third-party sharing platforms. Attackers spread the download links through targeted social engineering campaigns. They also utilize deceptive phishing messages. Victims must manually download and install the malicious application. This manual sideloading process bypasses official app store security checks entirely. Android malware operators frequently use this tactic. It allows them to reach potential victims directly without Google Play Protect interference. Users believe they are installing a legitimate utility or media application. Instead, they invite a destructive payload onto their devices.
The attackers target victims primarily in the Asia-Pacific region. Threat intelligence analysts recovered server logs revealing approximately 210 infected devices. The operators manage these compromised assets through a centralized web panel. The control panel displays the active connection status of each device. It also lists the specific phone model and network provider.
Infection Chain
Once installed, the application immediately requests device administrator privileges. It then asks the user for a broad set of highly sensitive permissions. These permissions include access to SMS messages, contacts, audio, and stored images. Finally, the malware requests accessibility service rights. This final step grants the attacker total control over the mobile device. The malware masks its true intentions by displaying a fake system lock screen. It records the PIN when the victim attempts to unlock the device. The application retrieves a unique AES encryption key from the remote server.
On devices running Android 9 or older, the malware performs a deep scan of shared external storage. As noted in the report, “The encryption engine utilizes the AES algorithm to lock the files.” After encryption, it deletes the original files. It appends a .enc extension to the locked copies. It also replaces local image files with graphic ransom notices. The ransomware actively avoids critical system folders. It skips the Android/data and Android/obb directories entirely. This precaution prevents the operating system from crashing during the encryption phase. A functional device ensures the victim can view the ransom note. On Android 10 and newer devices, native Scoped Storage rules restrict this scanning process.
Command-and-Control and Data-Exfiltration Behaviour
The malware secures its network traffic using HTTPS. It retrieves its active command-and-control domain from a predefined GitHub repository. This dynamic resolution technique ensures high operational resilience. Attackers can switch domains quickly if defenders block the primary address. During initial registration, the application extracts the device location, mobile operator, and OS version. The attackers use Firebase infrastructure to host an interactive extortion chat. The Zimperium report notes, “The malware initiates its cryptographic phase by executing dynamic key retrieval from the remote command-and-control (C2) server.”
The spyware component steals communication data rapidly. It intercepts one-time passwords from inbound SMS messages. It also extracts WhatsApp and Telegram chat histories by abusing accessibility services. Furthermore, it abuses the MediaProjection API to record device screens. It can capture static screenshots, stream live displays, and take silent photographs. The malware uploads these media payloads to the Catbox file hosting service. A newer version, Mantax v2, introduces WebSockets for faster communication. It also adds distinct psychological harassment features. It spawns intrusive alert dialog boxes in a rapid loop. It flashes startling image overlays every 600 milliseconds to disorient the user. It even abuses the Android Text-to-Speech engine to play custom audio threats through the physical speakers.
Defense or Detection Guidance
Security teams must enforce strict mobile device management policies. Organizations should prevent users from sideloading unapproved applications. Users must avoid downloading software from unofficial file-sharing links. IT administrators should train staff to recognize dangerous permission requests. Specifically, users should never grant accessibility or device administrator rights to unverified apps.
Defenders can block known network indicators, such as connections to the Catbox file hosting service. Security operations centers should monitor for unexpected Firebase domain connections. Administrators should deploy endpoint detection tools capable of identifying unauthorized MediaProjection usage. Updating mobile fleets to Android 10 or higher will restrict the file encryption blast radius. If an infection occurs, victims should disconnect the phone from the internet immediately. They must use a separate device to change passwords. Finally, they should enable multi-factor authentication across all compromised accounts.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!