Last seven days
- First activity
- Sep 10, 2026
- Last activity
- Sep 10, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
Mantax Otax is an Android hybrid ransomware and spyware family associated with likely Indonesian operators and victims.
Profile source: Mallory opens in a new tabMantax Otax
Mantax Otax is an Android hybrid ransomware and spyware family associated with likely Indonesian operators and victims. It is distributed through malicious sideloaded Android applications, including via phishing, shared links, messaging applications, and social-engineering lures. The malware requests device-administrator, sensitive runtime, and Accessibility permissions, enabling broad device control and screen-content access.
On Android 9 and earlier, Mantax Otax encrypts user files in shared storage using AES, deletes originals, displays ransom notices, and provides an attacker-operated chat interface for ransom negotiation. Android scoped-storage protections substantially reduce its file-encryption reach on Android 10 and later, but do not prevent its surveillance and data-theft functions.
Mantax Otax collects device, account, location, browser, contact, call-log, SMS, notification, gallery, and installed-application data. It can capture SMS one-time passwords, lock-screen PINs through fraudulent overlays, and WhatsApp and Telegram information through Accessibility-driven interaction. It captures screenshots, records and streams the display, covertly takes photographs with device cameras, and exfiltrates collected material to its operators. Later variants add remote application and screen blocking, touch interception, persistent dialogs, fullscreen multimedia overlays, and remote text-to-speech harassment to coerce victims into paying.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.