New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

September 12, 2026

A newly identified threat within the Android ecosystem, known as Mantax Otax, has emerged as a dual menace, intertwining ransomware with espionage capabilities. This sophisticated malware targets individuals who unwittingly install applications from dubious sources, creating a perilous situation that jeopardizes both their data and privacy.

New Android Ransomware

Mantax Otax operates by leveraging standalone Android application packages (APKs) that are often found on third-party file-sharing platforms. Victims may encounter these malicious links through various channels, including messaging apps or phishing attempts, which entice them to install applications outside of the official app store.

Researchers have traced the origins of this malware to Indonesian cybercriminals, noting linguistic markers and victim data that suggest a regional focus. The emergence of Mantax Otax highlights a troubling trend in mobile cybercrime, where surveillance, account theft, and file encryption converge into a single, multifaceted threat.

According to a report from Zimperium shared with Cyber Security News (CSN), the implications of this malware extend far beyond mere data loss. The theft of SMS one-time passwords, chat histories, and lock-screen PINs can empower criminals to infiltrate accounts and exert pressure on victims, paralleling other Android OTP theft campaigns that turn compromised devices into tools for account takeover.

Upon installation, Mantax Otax requests device-administrator rights and seeks access to SMS messages, contacts, audio files, and images. It then prompts users for Accessibility access, a legitimate Android feature that, when misused, allows the malware to read screen content and execute actions without user consent. This method is reminiscent of the tactics employed by the Crocodilus Android banking threat.

Malicious APKs are hosted on a third-party file-sharing platform (Source – Zimperium)

On devices running Android 9 and earlier, the ransomware scans external storage for images, videos, documents, and cryptographic keys. It encrypts these files using AES encryption, deletes the originals, and appends the .enc extension to the newly created files. Victims are then confronted with a ransom notice, informing them that their files have been encrypted and payment is required for recovery.

While the impact is somewhat mitigated on Android 10 and later versions due to Scoped Storage restrictions, the surveillance risk remains significant. After encryption, the malware can present an on-screen chat interface, enabling attackers to negotiate ransom payments directly, thereby setting the stage for potential double extortion.

Permission requested by the malware (Source – Zimperium)

OTP Theft Raises Account Risks

The malware’s capabilities extend beyond file encryption; it also collects a wealth of sensitive information, including contacts, call logs, browser history, location data, installed applications, device specifications, linked Google account settings, and gallery files. By monitoring notifications and incoming SMS messages, it places multi-factor authentication codes at risk. Furthermore, it targets WhatsApp profiles and Telegram credentials, utilizing Accessibility-driven actions to access conversations.

To further its malicious agenda, Mantax Otax employs a deceptive system-lock overlay, masquerading as a necessary security feature. This overlay obstructs access to the device while simultaneously capturing the PIN entered by the victim.

Victim’s device before and after the ransomware attack (Source – Zimperium)

The malware’s second iteration introduces WebSocket communications, app blocking, a transparent layer that absorbs touch inputs, disruptive pop-ups, full-screen video overlays, and remote text-to-speech messages.

To safeguard against such threats, users are advised to exercise caution before installing any application. It is crucial to steer clear of APKs promoted through unsolicited messages, social media posts, and unfamiliar file-sharing links, opting instead for trusted app stores. Users should also be vigilant in rejecting permissions related to Accessibility, administrator access, SMS, screen capture, or camera functions that do not align with an app’s intended purpose. This precaution is underscored by reports of fraudulent Android applications designed to steal PINs.

In the event of encountering an unfamiliar lock screen, persistent overlay, or unexpected permission requests, users should immediately disconnect their devices from networks and seek assistance from trusted sources before entering any passwords or PINs. Organizations are encouraged to monitor managed devices for signs of sideloaded applications, unusual Accessibility activations, screen capture requests, and unexpected outbound traffic.

Type Indicator Description
C2 domain hxxps://apimantax[.]otax[.]fun Active command-and-control domain dynamically retrieved by Mantax Otax from a GitHub repository.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24 hours of their emergence. Try ANYRUN to prevent incidents with early detection.

AppWizard