NewsTradingSentimentCalendarCommunityBriefing
Tech

Android malware Mantax Otax combines ransomware and spying

By Tech Desk · 2026-09-11 · 2 min read
A cracked smartphone screen with a digital padlock symbol floating above it
Illustration: Tradingbird

A new malware strain called Mantax Otax targets Android users by encrypting files and stealing sensitive data, while also harassing victims to force payment.

A new Android malware strain known as Mantax Otax is combining the destructive power of ransomware with the invasive reach of spyware. According to BleepingComputer, this threat does more than just lock files; it actively monitors user behavior, steals personal information, and uses harassment tactics to pressure victims into paying a ransom.

The attackers distribute the malware through malicious application files hosted outside the official Google Play Store. They use phishing messages and social engineering techniques to trick users into installing the app. Once installed, the malware requests permissions that grant it extensive control over the device, setting the stage for a multi-faceted attack.

Targeting older Android versions

Mantax Otax specifically targets devices running Android version 9 or older. This limitation exists because newer Android versions introduced security features that restrict how apps access storage. By focusing on older systems, the malware can more easily encrypt files in shared storage using a unique key sent from a remote server.

After encrypting the files, the malware deletes the original copies and adds a specific extension to the encrypted versions. It also replaces local images with ransom notes and opens a chat window to negotiate payment. Security researchers found that the attackers used a cloud service to communicate with victims, a configuration error that exposed their conversations.

Stealing data and spying

Beyond encryption, the malware acts as a sophisticated spy. It can steal lock screen passwords to maintain access, read text messages, and access call logs and contacts. It also targets messaging applications like WhatsApp and Telegram, extracting profiles and chat histories by simulating user actions.

The malware can also capture screenshots, record videos, and stream the victim’s screen in near real-time to a file hosting service. It can even use the device’s cameras to take photographs and upload them to the operators. This level of surveillance allows attackers to gather highly sensitive personal and professional data.

Harassment as a pressure tactic

Version two of the malware introduced features designed to intimidate and harass users. It triggers repeated dialog boxes, plays full-screen videos, and displays rapid image overlays that act as jump scares. It also uses text-to-speech to play messages through the device speakers.

These actions are not random; they are a deliberate strategy to create stress and urgency. The goal is to make the victim feel overwhelmed and pressured into paying the ransom quickly. While up-to-date devices with active security services can detect and block this malware, users should avoid installing apps from untrusted sources and be cautious about granting extensive permissions.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories