Skip to main content
LiMP VPN
All news

Mantax Otax: Android Trojan Encrypts Files and Spies on Users

Mantax Otax: Android Trojan Encrypts Files and Spies on Users

In short: Zimperium researchers uncovered Mantax Otax, an Android threat combining file-encrypting ransomware with full-featured spyware. It steals SMS messages, OTP tokens, WhatsApp and Telegram conversations, and records screen and both cameras — all while demanding ransom. Highest risk for devices on Android 9 or older, though spyware features remain active on newer versions.

What Is Mantax Otax

In early September 2026, Zimperium published a detailed analysis of a new Android threat named Mantax Otax. Its distinguishing feature is the combination of two attack classes previously used separately: ransomware and spyware. Russian security outlets Anti-Malware.ru and ITSec.ru reported on it in mid-September 2026.

This combination enables double-extortion: attackers do not just lock files and demand payment — they also threaten to publish stolen messages and photos. Zimperium attributed the campaign to Indonesian operators.

How the Trojan Attacks a Phone

After obtaining administrator rights, Mantax Otax runs several tasks simultaneously:

  • File encryption. The malware scans storage for documents, archives, databases, media files, and cryptographic keys. Each infected device receives a unique AES key; originals are deleted and encrypted copies saved with the .enc extension. On Android 9 and older, full file-system access is unrestricted.
  • Data theft. The trojan steals PIN codes, SMS messages, OTP tokens, contacts, call logs, browser history, Google account credentials, and WhatsApp and Telegram conversations.
  • Covert recording. Via the Android MediaProjection API, the malware streams a real-time screen copy to its operators and activates both cameras to upload photos.
  • Psychological pressure. Every 600 milliseconds, full-screen horror videos and ransom-demand dialogs appear. A text-to-speech engine delivers threats through the speaker.

Concerned about mobile privacy? See how LiMP VPN protects your traffic — especially on public networks where phishing links spread fastest.

Who Is at Risk

Mantax Otax is most dangerous on Android 9 or earlier. From Android 10 onward, Scoped Storage restricts app file-system access, substantially limiting the ransomware component. Spyware features — SMS theft, OTP interception, screen recording — remain fully active on modern Android versions.

Users of older phones without security updates are disproportionately exposed. We covered a related threat, the RatHat banking trojan, in a separate article.

How the Malware Spreads

Mantax Otax is distributed exclusively outside Google Play: through third-party APK hosts, phishing messages, and social engineering. Victims are tricked into installing an "update" to a popular app, then granting administrator and Accessibility Services permissions. Google Play Protect already detects and blocks Mantax Otax at installation.

How to Protect Your Phone

  • Never install APKs from outside Google Play. The official store with Play Protect enabled is your primary defence.
  • Keep Android updated. Android 10+ Scoped Storage limits ransomware reach. A phone without security patches is a liability.
  • Deny Accessibility permissions to unknown apps. These grant deep device control — only trust reputable, well-known apps with them.
  • Enable Google Play Protect. It detects Mantax Otax. Verify it is active in Play Store settings.
  • Back up your data regularly. A backup minimises damage if ransomware strikes.
  • Use an encrypted connection on public Wi-Fi. A VPN encrypts your traffic and hides your activity. Read more on our security blog.

Sources

Mantax Otax: Android Trojan Encrypts Files and Spies on Users