Zimperium Uncovers Mantax Otax Android Malware Combining Theft, Surveillance and Ransomware
Zimperium has identified Mantax Otax, an Android malware that steals data, remotely monitors victims and encrypts files for ransom, mainly affecting older Android devices and distributed through third-party app channels.
Mantax Otax is distributed as a standalone APK, meaning it can appear on third-party app stores, Telegram channels, forums and social media, TechRadar reported. There are no traces of the malware on official repositories including the Google Play Store or Samsung's Galaxy Store. Zimperium also speculated that it is likely being distributed through phishing emails. It is not known how many people are infected, or whether the campaign is aimed primarily at business users or individuals in general. The type of app that Mantax Otax spoofs is also unknown, making it difficult to assess who the intended targets are.
The malware primarily targets users with older Android phones. Versions 9 and older are most at risk because attackers can use all of the malware's features on those devices. On modern devices running Android 10 and above, Zimperium said the malware's effectiveness is severely hindered by native operating system defenses, specifically Scoped Storage restrictions. Those sandboxing rules constrain the ransomware to scanning only the application's localized external files directory, reducing the number of accessible user files. Newer devices and users of Zimperium's Mobile Threat Defense and Runtime Application Protection are said to be protected at the software level.
Mantax Otax first asks for administrator privileges and then grants itself an extensive list of capabilities, including access to SMS messages, contacts, audio and images, according to the report. It then requests accessibility permissions, taking full control of the compromised device. The malware steals browser history, contacts, call logs, SMS messages, notifications, files, gallery media, Google account information, device specifications, location data and application inventories. It can also pull WhatsApp information such as messages and profiles, and on Telegram it can retrieve lock-screen PINs.
Beyond data theft, Mantax Otax acts as a remote monitoring tool. It can take screenshots, record the screen or livestream it directly to attackers, and it can take photos using both the front and rear cameras. Zimperium did not mention microphone-recording capabilities. After harvesting data, the malware encrypts user files with AES, deletes the originals and appends a .enc extension. Victims are then shown a chat interface where they can communicate with the attackers and negotiate a ransom payment in exchange for getting their device back.
Zimperium found two separate versions of Mantax Otax, with one described as an evolution of the other. The researchers said it had modified its network traffic behavior to use WebSockets and introduced a set of new commands. Ransomware operators often prefer targeting businesses rather than individuals because disrupted operations can cause greater losses, although individual victims have not disappeared from the target list. Because the spoofed app remains unidentified, the available information does not show whether this campaign is focused on companies or consumers.