Mantax Otax: The Android Malware That Locks Your Files, Then Screams At You Until You Pay
Indonesian operators are pushing an unusual Android malware that combines file-locking ransomware with spyware, screen recording and 'jumpscare' harassment tactics designed to bully victims into paying.

Key points
- Zimperium researchers have identified a new Android malware family called Mantax Otax, run by Indonesian operators and spread through malicious app installers hosted outside the Google Play store.
- The malware locks personal files on older Android phones, steals messages and PINs, records the screen, and then harasses victims with pop-ups, loud audio and full-screen scare images to pressure them into paying a ransom.
- The file-locking part only works on devices running Android 9 or older, because a privacy feature added in Android 10 called Scoped Storage blocks the technique.
- Zimperium found a misconfiguration in the attackers' chat server and was able to read live negotiations between the criminals and their victims.
- Google Play Protect, the built-in security scanner on Android, already blocks the malware on up-to-date devices.
A new Android malware strain is doing something unusual. It locks your files like ransomware, spies on you like commercial stalkerware, and then actively harasses you with pop-ups and scary noises until you pay.
Mobile security firm Zimperium calls it Mantax Otax, and says the operators appear to be based in Indonesia. The findings, detailed in a Zimperium writeup and first reported by BleepingComputer, describe a toolkit that reads more like a hostage situation than a typical piece of malware.
How does the malware get onto a phone?
Victims install it themselves, after being tricked. The operators send phishing messages, meaning fake texts and chat messages designed to look legitimate, that push people to download an APK. An APK is the installer file for an Android app, and these ones sit on websites outside the official Google Play store.
Once installed, the app asks for permission to use Android's Accessibility service. That service is meant to help people with disabilities control their phones by voice or gesture. Give it to the wrong app and you have handed over near-total control of the device.
From there, the malware quietly contacts a server run by the criminals, known as a command-and-control server, to fetch instructions. It reports back the phone's location, mobile carrier, Android version and device ID.
What does it actually do to the victim?
On older phones, it encrypts files. Encryption scrambles the contents so only someone with the right key can read them. Mantax Otax hunts through the phone's shared storage, scrambles the files it finds, deletes the originals and renames the scrambled copies with a '.enc' ending.
It then replaces the photos on the phone with ransom notes and opens a full-screen chat window for the victim to negotiate payment.
The encryption only works on Android 9 and earlier. Newer versions include Scoped Storage, a rule that stops apps from rummaging through files that do not belong to them.
But the spying works on any version. The malware can:
- Steal the lock-screen PIN using a fake overlay screen.
- Read text messages, including the one-time codes banks send to verify logins.
- Pull contacts, call logs, browsing history and Google account details.
- Copy WhatsApp and Telegram chats by silently tapping through the apps.
- Record the screen as video, take photos through the camera, and stream the live screen back to the attacker.
| Feature | What it does | Works on |
|---|---|---|
| File encryption | Locks personal files, demands ransom | Android 9 and older |
| PIN theft | Fake lock screen captures the code | All versions |
| Chat theft | Reads WhatsApp and Telegram messages | All versions |
| Screen recording | Records or live-streams the screen | All versions |
| Harassment mode | Jumpscare images, forced audio, pop-ups | Version 2 onward |
Why is the harassment part getting attention?
Because it is designed to break the victim down. Version 2 of Mantax Otax added repeated pop-up dialogs, full-screen videos, rapid 'jumpscare' images, and text-to-speech messages the attacker can play through the phone's speaker from anywhere.
The point is intimidation. Pay, or the phone keeps screaming at you.
In a small piece of good news, Zimperium's researchers found the attackers had misconfigured their chat server, hosted on Google's Firebase platform. That mistake let the researchers read the criminals' conversations with victims directly.
Should ordinary Android users be worried?
Probably not, if you stick to the basics. Google Play Protect, the security scanner built into Android, already recognises and blocks Mantax Otax on phones that are up to date.
Do not install apps from links sent in messages, even from people you know. Do not grant Accessibility permission to an app unless you specifically need it for accessibility. If a phone still runs Android 9 or older, treat it as end-of-life and avoid using it for banking or private photos.
Anyone who thinks they have installed a bad APK should disconnect the phone from wifi and mobile data, and factory reset it from recovery mode.



