New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links.
Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s cameras, making one infection both an extortion and privacy crisis.
The campaign appears built around standalone Android app packages, or APKs, hosted on third-party file-sharing services.
Victims can be led to them through shared links, messaging apps or phishing messages, then persuaded to install the app outside the official store.
Its researchers linked the activity to Indonesian threat actors and found language clues and victim files suggesting an Indonesian focus. The discovery shows how mobile criminals are bringing surveillance, account theft and file encryption together in one package.
Zimperium said in a report shared with Cyber Security News (CSN) that the impact can go far beyond losing access to photos or documents.
Stolen SMS one-time passwords, chats and lock-screen PINs can give criminals the information needed to enter accounts or pressure victims. The combination resembles other Android OTP theft campaigns that turn a compromised phone into an account-takeover tool.
New Android Ransomware
After installation, Mantax Otax asks for device-administrator rights and then seeks access to SMS, contacts, audio and images.
It ultimately asks for Accessibility access, a legitimate Android feature designed to assist users but one that can be abused to read screen content and perform actions. This permission path is also central to the Crocodilus Android banking threat.

On Android 9 and older versions, the ransomware searches shared external storage for images, videos, documents and cryptographic keys.
It encrypts targeted files with AES, deletes the originals and adds the .enc extension to the replacements. It also overwrites local images with a ransom notice telling victims their files were encrypted and must be paid for.
The damage is more limited on Android 10 and later because Scoped Storage restricts the app mostly to its own external-files area.
However, that restriction does not remove the surveillance danger. Following encryption, the malware can display an on-screen chat function that lets attackers negotiate a ransom directly, creating conditions for double extortion.

Mantax Otax also abuses Android’s MediaProjection function to take screenshots, record the screen as MP4 video and stream display content almost in real time.
Captured screenshots are uploaded to Catbox before associated URLs return to the operators. Similar screen-viewing abuse appeared in the recent StreamRAT mobile campaign, where operators could watch and manipulate victims’ phones.
The spyware component can additionally open either camera through a hidden preview surface and take photographs without visible interaction. The image is compressed, stored locally, encoded and sent to the attacker.
OTP Theft Raises Account Risks
The malware gathers contacts, call logs, browser history, location data, installed apps, device information, linked Google-account settings and gallery files.
It monitors notifications and inbound SMS messages, placing multi-factor authentication codes at risk. It also targets WhatsApp profiles and messages, plus Telegram credentials and chat history, using Accessibility-driven clicks to open conversations.
A fake system-lock overlay adds another route to credential theft. Mantax Otax presents itself as a necessary lock process, blocks access and captures the PIN a victim enters.

Its second version adds WebSocket communications, app blocking, a transparent layer that absorbs touch input, disruptive pop-ups, full-screen video overlays and remote text-to-speech messages.
The practical defense begins before an app is installed. People should avoid APKs promoted through unsolicited messages, social posts and unfamiliar file-sharing links, and install software through trusted stores.
They should reject Accessibility, administrator, SMS, screen-capture or camera permissions that do not match an app’s purpose, a precaution reinforced by reporting on fake Android apps stealing PINs.
Anyone who sees an unfamiliar lock screen, persistent overlay or unexpected permission request should disconnect the phone from networks and seek trusted support before entering passwords or PINs.
Organisations should watch managed devices for sideloaded apps, unusual Accessibility activation, screen-capture requests and unexpected outbound traffic.
| Type | Indicator | Description |
|---|---|---|
| C2 domain | hxxps://apimantax[.]otax[.]fun | Active command-and-control domain dynamically retrieved by Mantax Otax from a GitHub repository. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims appeared first on Cyber Security News.




















