Researchers identified Mantax Otax, an Android hybrid spyware and ransomware family attributed to Indonesian threat actors and apparently targeting Indonesian users. Distributed through sideloaded APKs, it seeks device-administrator, sensitive runtime, and Accessibility permissions to gain extensive control, steal personal and communications data, capture screenshots and camera images, and—on Android 9 and earlier—encrypt user files with AES before demanding payment through an attacker-controlled chat interface.
A newer Mantax Otax v2 variant uses WebSockets to support persistent screen and application blocking, touch interception, overlay and dialog spam, jumpscare effects, and remote text-to-speech harassment. Its ability to capture GUI input and inject or interfere with user input aligns with mobile ATT&CK techniques T1417.002 and T1516, increasing both the surveillance and coercive impact on compromised devices.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers detailed Mantax Otax's AES file encryption and .enc extension behavior, screen and covert-camera capture, OTP theft, messaging-data collection, and fake lock-screen PIN capture. The analysis identified apimantax[.]otax[.]fun as an active C2 domain retrieved dynamically through GitHub and described a second version using WebSockets and disruptive device-control features.
A report identified Mantax Otax as an Android threat attributed to Indonesian actors that combines surveillance, device control, file encryption, and extortion. The analyzed malware uses sideloaded APKs, retrieves C2 infrastructure through GitHub, and includes an evolved v2 variant using WebSockets and expanded device-locking and harassment functions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcexakep.ru
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourcezimperium.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.