Zimperium’s zLabs uncovered Mantax Otax v2, a highly aggressive Android threat linked to Indonesian actors that combines spyware, data theft, remote surveillance, and ransomware in one campaign. It uses phishing and sideloaded APKs, then steals credentials and personal data, records screens and photos, and encrypts files on older Android devices while coordinating extortion through Firebase and a dynamic C2 infrastructure. #MantaxOtax #Firebase #Android
Keypoints
- Mantax Otax is a hybrid Android malware family that blends spyware, ransomware, and extortion into one attack chain.
- The campaign is linked to Indonesian threat actors and appears to specifically target Indonesian victims.
- Initial infection can occur through sideloaded malicious APKs shared via file-sharing services, messaging platforms, phishing, and social engineering.
- The malware requests device administrator, SMS, contacts, audio, image, and accessibility permissions to gain broad control over the device.
- It uses dynamic C2 resolution, device registration, and Firebase-based command handling to maintain resilience and manage infected devices.
- On Android 9 and earlier, it encrypts files with AES, appends a .enc extension, and replaces content with ransom notices; Android 10+ is less affected due to Scoped Storage.
- Beyond encryption, it steals PINs, messages, calls, browser history, photos, location data, screen content, and can abuse the camera, overlays, and text-to-speech for harassment.
MITRE Techniques
- [T1660 ] Phishing – The malware is distributed through social engineering and phishing messages to trick users into installing the malicious APK (‘users are persuaded to download and install the application manually through shared links, messaging platforms, social engineering campaigns, and phishing messages’).
- [T1655.001 ] Masquerading: Match Legitimate Name or Location – The malware disguises itself as legitimate system activity and apps, including a fake lock process and pretending to be a legitimate app (‘masquerading as a legitimate system lock process’, ‘pretending to legit app like Grok’).
- [T1516 ] Input Injection – It simulates user actions, blocks touch input, and overlays fake screens or prompts to manipulate the victim (‘mimics user interaction, perform clicks and various gestures’, ‘creates a transparent full-screen overlay that intercepts all touch events’).
- [T1453 ] Abuse Accessibility Features – The malware requests accessibility permissions and uses accessibility services to harvest messages and perform actions (‘requesting accessibility permissions’, ‘harvests WhatsApp account profiles and messages using Accessibility services’).
- [T1417.002 ] Input Capture: GUI Input Capture – It captures what is displayed on the screen, including lock screen PIN entry and visible UI content (‘intercepts the user’s lock screen PIN’, ‘It is able to get the shown UI’).
- [T1517 ] Access Notifications – It monitors notifications and incoming messages to collect sensitive content such as OTPs (‘intercepts system notifications’, ‘registers a receiver to monitor incoming SMS messages’).
- [T1430 ] Location Tracking – It collects and transmits the victim’s geographic location during registration and surveillance (‘exfiltrates critical host telemetry, including the victim’s geographic location’).
- [T1418 ] Software Discovery – It enumerates installed applications and app inventories on the device (‘local application inventories’).
- [T1426 ] System Information Discovery – It gathers device details such as hardware specifications, Android version, network operator, and Android ID (‘hardware specifications’, ‘Android OS version’, ‘unique Android ID’).
- [T1513 ] Screen Capture – It records the screen, captures screenshots, and streams display content via MediaProjection (‘recording device screens in real-time’, ‘static screenshot capture, full-motion screen recording’).
- [T1429 ] Audio Capture – It accesses audio and can collect recordings from the device (‘access to SMS messages, contacts, audio, and images’, ‘captures Audio recordings’).
- [T1616 ] Call Control – It can block calls and manipulate call handling through malware routines (‘can disable calls’, ‘can make and block call in the device’).
- [T1636.004 ] Protected User Data: SMS Messages – It steals SMS messages and can capture OTPs delivered by text (‘harvests contact lists, call logs, and SMS messages’, ‘Steals SMSs from the infected device’).
- [T1646 ] Exfiltration Over C2 Channel – It sends stolen screenshots, recordings, and other data back to the operators through C2/Firebase infrastructure (‘transmitted directly back to the operator’, ‘Sending exfiltrated data over C&C server’).
- [T1582 ] SMS Control – It can read and send SMS messages as part of device manipulation and data theft (‘It can read and send SMS’).
Indicators of Compromise
- [Domain/URL ] C2 infrastructure and dynamic resolution source – hxxps://apimantax[.]otax[.]fun, GitHub repository
- [File type ] Malicious Android payloads distributed as standalone apps – Android APK, side-loaded APK
- [File extension ] Encrypted victim files – .enc, encrypted variants
- [Cloud service / exfiltration target ] Screenshot and video storage/exfiltration – Catbox, Firebase
- [File format ] Captured surveillance outputs – JPEG screenshots, MP4 screen recordings
Read more: https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration