In short: Zimperium researchers uncovered Mantax Otax, an Android threat combining file-encrypting ransomware with full-featured spyware. It steals SMS messages, OTP tokens, WhatsApp and Telegram conversations, and records screen and both cameras — all while demanding ransom. Highest risk for devices on Android 9 or older, though spyware features remain active on newer versions.
What Is Mantax Otax
In early September 2026, Zimperium published a detailed analysis of a new Android threat named Mantax Otax. Its distinguishing feature is the combination of two attack classes previously used separately: ransomware and spyware. Russian security outlets Anti-Malware.ru and ITSec.ru reported on it in mid-September 2026.
This combination enables double-extortion: attackers do not just lock files and demand payment — they also threaten to publish stolen messages and photos. Zimperium attributed the campaign to Indonesian operators.
How the Trojan Attacks a Phone
After obtaining administrator rights, Mantax Otax runs several tasks simultaneously:
- File encryption. The malware scans storage for documents, archives, databases, media files, and cryptographic keys. Each infected device receives a unique AES key; originals are deleted and encrypted copies saved with the
.encextension. On Android 9 and older, full file-system access is unrestricted. - Data theft. The trojan steals PIN codes, SMS messages, OTP tokens, contacts, call logs, browser history, Google account credentials, and WhatsApp and Telegram conversations.
- Covert recording. Via the Android MediaProjection API, the malware streams a real-time screen copy to its operators and activates both cameras to upload photos.
- Psychological pressure. Every 600 milliseconds, full-screen horror videos and ransom-demand dialogs appear. A text-to-speech engine delivers threats through the speaker.
Concerned about mobile privacy? See how LiMP VPN protects your traffic — especially on public networks where phishing links spread fastest.
Who Is at Risk
Mantax Otax is most dangerous on Android 9 or earlier. From Android 10 onward, Scoped Storage restricts app file-system access, substantially limiting the ransomware component. Spyware features — SMS theft, OTP interception, screen recording — remain fully active on modern Android versions.
Users of older phones without security updates are disproportionately exposed. We covered a related threat, the RatHat banking trojan, in a separate article.
How the Malware Spreads
Mantax Otax is distributed exclusively outside Google Play: through third-party APK hosts, phishing messages, and social engineering. Victims are tricked into installing an "update" to a popular app, then granting administrator and Accessibility Services permissions. Google Play Protect already detects and blocks Mantax Otax at installation.
How to Protect Your Phone
- Never install APKs from outside Google Play. The official store with Play Protect enabled is your primary defence.
- Keep Android updated. Android 10+ Scoped Storage limits ransomware reach. A phone without security patches is a liability.
- Deny Accessibility permissions to unknown apps. These grant deep device control — only trust reputable, well-known apps with them.
- Enable Google Play Protect. It detects Mantax Otax. Verify it is active in Play Store settings.
- Back up your data regularly. A backup minimises damage if ransomware strikes.
- Use an encrypted connection on public Wi-Fi. A VPN encrypts your traffic and hides your activity. Read more on our security blog.
