Der kostenlose Scanner prüft, ob Ihr Computer infiziert ist.
JETZT ENTFERNENUm das Produkt mit vollem Funktionsumfang nutzen zu können, müssen Sie eine Lizenz für Combo Cleaner erwerben. Auf 7 Tage beschränkte kostenlose Testversion verfügbar. Eigentümer und Betreiber von Combo Cleaner ist RCS LT, die Muttergesellschaft von PCRisk.
Was für eine Malware ist Mantax Otax?
Mantax Otax ist eine Android-Ransomware mit integrierten Spyware-Funktionen, die auf Nutzer in Indonesien abzielt. Sie verschlüsselt Dateien auf dem Gerät, sperrt den Bildschirm und drängt die Opfer in einen Chat mit den Angreifern, während sie heimlich Nachrichten, Fotos, Passwörter und andere persönliche Daten stiehlt. Die Malware wurde erstmals vom zLabs-Team von Zimperium analysiert.

Mantax Otax malware overview
Mantax Otax is linked to Indonesian threat actors, and two versions of it have been found so far, with the second building on the first. Language clues and files recovered from victims show that the operators focus on Indonesian users.
Right after installation, the malware asks for device administrator rights. The admin prompt openly lists abilities such as erasing all data, changing the screen lock, locking the screen, and disabling cameras. It then requests access to the camera, SMS messages, contacts, audio, and images, along with permission to display content over other apps.
The last step is a request for Accessibility Services access, shown as an Indonesian-language pop-up that asks the victim to enable both Accessibility and notification access. Once granted, this gives the attackers broad control over the device, including the ability to read what is on the screen and tap on the victim's behalf.
Mantax Otax talks to its command-and-control (C2) server over HTTPS. Instead of storing the server address in its code, it pulls the current domain (apimantax[.]otax[.]fun) from a GitHub repository. This lets the operators move to a new server whenever the old one gets blocked, without having to update the malware itself.
The malware then gives the device a unique ID and registers it with the server. The registration data includes the phone model and manufacturer, Android version, country, mobile carrier, and even whether a lock screen PIN has been set. After that, it waits for commands, which are delivered through Firebase.
For the ransomware part, Mantax Otax requests an encryption key from the C2 server. Each key is tied to the victim's Android ID, so every infected device gets a different one. The malware then looks for photos, videos, documents, archives, databases, and cryptographic key files, locks them with AES encryption, and deletes the originals.
Encrypted files keep their original name with .enc added to the end (for example, sample_image.jpg.enc). Some images are also swapped for altered copies stamped with the message "Your files have been encrypted. Pay to decrypt." In Zimperium's test, gallery thumbnails turned into blank file icons, with one picture replaced by red ransom text.
How much damage this does depends on the Android version. On Android 9 or older, the malware digs through the entire shared storage, skipping only the system folders it needs to leave alone to avoid crashing the phone. Android 10 and newer use a protection called Scoped Storage, which confines the malware to its own app folder and greatly limits the number of files it can reach.
Once encryption is done, a full-screen chat window titled SYSTEM PROTECTED takes over the display, and the attacker appears in it as Mantax Bro!!. This is where victims are told to negotiate a payment. Because the operators misconfigured their Firebase server, Zimperium was able to read these conversations, including messages from victims begging to get their files back.
Combined with the data theft described below, this puts victims in a double-extortion situation, where both their files and their personal information are in the attackers' hands.
Mantax Otax can also lock the phone behind a fake system lock screen. One version reads SYSTEM PROTECTED, claims the device is under an administrative lock, and carries Manta X2 Elite Security branding, while another is written in Indonesian. Both ask for a PIN, so victims end up handing their real lock screen code straight to the attackers.
The spyware side is just as broad. By abusing Android's built-in screen recording feature (the MediaProjection API), the malware can take screenshots, record the screen as MP4 videos, and stream the display live to the attackers. Screenshots and recordings are uploaded to the free file host Catbox, and the download links are sent to the operators.
On top of that, Mantax Otax collects contacts, call logs, incoming SMS messages (including one-time passwords used for logins), notifications, browser history, installed apps, location, linked Google accounts, files, and gallery photos. Through Accessibility Services, it also steals WhatsApp profiles and messages, as well as Telegram account details and chats, by opening conversations on its own and copying their contents.
The malware can secretly take photos with the front or rear camera, with no visible sign on the screen. The photos are compressed, encoded in Base64, and sent to the operators - leaked server records show them being stored on Catbox as well.
Files exposed by the misconfigured server also included a screenshot of the operators' control panel, branded Manta Controller. At the time, it listed 210 infected devices (only two of them online), including phones from vivo, Infinix, and Xiaomi.
The second version switches to WebSocket connections through another subdomain (apixnxx[.]otax[.]fun) and adds new commands aimed at controlling and tormenting victims. It can lock the screen with an Indonesian-language message claiming that the device is controlled by Manta X2, that all activity is being watched, and that the victim must contact an admin to regain access.
Version 2 can also block individual apps and place an invisible layer over the entire screen that swallows every tap and swipe, leaving the phone visible but unusable. Other commands flood the display with pop-up dialogs, play a full-screen video to hide what is happening in the background, or flash scary images every 600 milliseconds to create a disorienting strobe effect.
The operators can even make the phone talk. A remote text-to-speech command reads out any message the attackers choose through the device speaker, with adjustable language, speed, and pitch.
In summary, the presence of software like Mantax Otax on devices can lead to multiple system infections, serious privacy issues, financial losses, and identity theft. Victims risk losing their photos and documents, their accounts, and their private conversations all at once.
It has to be mentioned that malware developers often improve upon their software and methodologies. Hence, potential future iterations of Mantax Otax could have additional or different functionalities and features.
| Name | Mantax Otax Trojaner |
| Threat Type | Android malware, malicious application, ransomware, spyware, unwanted application. |
| Detection Names | Avast-Mobile (Android:Evo-gen [Trj]), Combo Cleaner (Android.Riskware.SpyAgent.OV), ESET-NOD32 (Android/Spy.Agent.GGC Trojan), Kaspersky (HEUR:Backdoor.AndroidOS.Agent.iz), Full List (VirusTotal) |
| Symptoms | Files are encrypted and renamed with the .enc extension, the screen is locked by a fake system lock or chat window, the device is running slow, data and battery usage is increased significantly, questionable applications appear, pop-ups and overlays block normal use. |
| Distribution methods | APK files on third-party file-sharing services, links shared via messaging apps, phishing messages, social engineering, apps disguised as legitimate or adult-content applications. |
| Damage | Encrypted files, locked device, stolen personal information (private messages, logins/passwords, one-time passwords, photos, etc.), decreased device performance, battery is drained quickly, decreased Internet speed, huge data losses, monetary losses, stolen identity (malicious apps might abuse communication apps). |
| Malware-Entfernung (Windows) |
Um mögliche Malware-Infektionen zu entfernen, scannen Sie Ihren Computer mit einer legitimen Antivirus-Software. Unsere Sicherheitsforscher empfehlen die Verwendung von Combo Cleaner. Combo Cleaner herunterladenDer kostenlose Scanner überprüft, ob Ihr Computer infiziert ist. Um das Produkt mit vollem Funktionsumfang nutzen zu können, müssen Sie eine Lizenz für Combo Cleaner erwerben. Auf 7 Tage beschränkte kostenlose Testversion verfügbar. Eigentümer und Betreiber von Combo Cleaner ist RCS LT, die Muttergesellschaft von PCRisk. |
Conclusion
Mantax Otax is a nasty combination of ransomware and spyware. It can lock a victim out of their phone and files, pressure them into paying through a chat window, and at the same time collect nearly everything stored on or shown by the device. Even if files are recovered, the stolen messages, codes, and photos remain a long-term risk.
Other examples of Android-specific malware include Manic, WindRelay, and Rokarolla. Malicious apps like these tend to request extensive permissions and abuse them to steal data, spy on users, or take over the device entirely.
How did Mantax Otax infiltrate my device?
Zimperium found Mantax Otax samples hosted as APK files on a third-party file-sharing service, where one of them was offered under the name VoCNewEra. Links to such files are usually spread through messaging apps, phishing messages, and other social engineering tricks. Since the app is not on the Google Play Store, victims have to manually allow its installation.
The lures seen so far include an app with an Indonesian name hinting at adult content, and some samples reportedly pose as legitimate apps such as Grok. Cybercriminals rely on disguises like these because curious or trusting users are more likely to tap through the long list of permission requests without thinking twice.
How to avoid installation of malware?
Install apps only from the Google Play Store or the developer's official website, and be wary of APK files shared through file-hosting links, chats, or social media - even when a friend sends them. Pay attention to the permissions an app asks for. A video player, chatbot, or game has no reason to need administrator rights, Accessibility Services, or the ability to read your SMS messages.
Keep Android and your apps updated, since newer Android versions limit what malware like this can reach. Ignore unexpected messages that push you to download something, and avoid adult, cracked, or "premium for free" apps from unofficial sources. It also helps to have a reputable mobile antivirus installed and to back up important photos and documents regularly.
Mantax Otax APK hosted on a third-party file-sharing website (source: zimperium.com):

Permission requests displayed by Mantax Otax during installation (source: zimperium.com):

Files on an infected device before and after Mantax Otax encryption (source: zimperium.com):

Fake lock screens used by Mantax Otax to steal the victim's PIN (source: zimperium.com):

Screen-blocking message shown by the second version of Mantax Otax (source: zimperium.com):

Quick menu:
- Introduction
- How to delete browsing history from the Chrome web browser?
- How to disable browser notifications in the Chrome web browser?
- How to reset the Chrome web browser?
- How to delete browsing history from the Firefox web browser?
- How to disable browser notifications in the Firefox web browser?
- How to reset the Firefox web browser?
- How to uninstall potentially unwanted and/or malicious applications?
- How to boot the Android device in "Safe Mode"?
- How to check the battery usage of various applications?
- How to check the data usage of various applications?
- How to install the latest software updates?
- How to reset the system to its default state?
- How to disable applications that have administrator privileges?
Delete browsing history from the Chrome web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "History" in the opened dropdown menu.

Tap "Clear browsing data", select "ADVANCED" tab, choose the time range and data types you want to delete and tap "Clear data".
[Zurück zum Inhaltsverzeichnis]
Disable browser notifications in the Chrome web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "Settings" in the opened dropdown menu.

Scroll down until you see "Site settings" option and tap it. Scroll down until you see "Notifications" option and tap it.

Find the websites that deliver browser notifications, tap on them and click "Clear & reset". This will remove permissions granted for these websites to deliver notifications. However, once you visit the same site again, it may ask for a permission again. You can choose whether to give these permissions or not (if you choose to decline the website will go to "Blocked" section and will no longer ask you for the permission).
[Zurück zum Inhaltsverzeichnis]
Reset the Chrome web browser:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you find "Chrome" application, select it and tap "Storage" option.

Tap "MANAGE STORAGE", then "CLEAR ALL DATA" and confirm the action by taping "OK". Note that resetting the browser will eliminate all data stored within. This means that all saved logins/passwords, browsing history, non-default settings and other data will be deleted. You will also have to re-login into all websites as well.
[Zurück zum Inhaltsverzeichnis]
Delete browsing history from the Firefox web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "History" in the opened dropdown menu.

Scroll down until you see "Clear private data" and tap it. Select data types you want to remove and tap "CLEAR DATA".
[Zurück zum Inhaltsverzeichnis]
Disable browser notifications in the Firefox web browser:

Visit the website that is delivering browser notifications, tap the icon displayed on the left of URL bar (the icon will not necessarily be a "Lock") and select "Edit Site Settings".

In the opened pop-up opt-in the "Notifications" option and tap "CLEAR".
[Zurück zum Inhaltsverzeichnis]
Reset the Firefox web browser:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you find "Firefox" application, select it and tap "Storage" option.

Tap "CLEAR DATA" and confirm the action by taping "DELETE". Note that resetting the browser will eliminate all data stored within. This means that all saved logins/passwords, browsing history, non-default settings and other data will be deleted. You will also have to re-login into all websites as well.
[Zurück zum Inhaltsverzeichnis]
Uninstall potentially unwanted and/or malicious applications:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you see a potentially unwanted and/or malicious application, select it and tap "Uninstall". If, for some reason, you are unable to remove the selected app (e.g., you are prompted with an error message), you should try using the "Safe Mode".
[Zurück zum Inhaltsverzeichnis]
Boot the Android device in "Safe Mode":
The "Safe Mode" in Android operating system temporarily disables all third-party applications from running. Using this mode is a good way to diagnose and solve various issues (e.g., remove malicious applications that prevent users you from doing so when the device is running "normally").

Push the "Power" button and hold it until you see the "Power off" screen. Tap the "Power off" icon and hold it. After a few seconds the "Safe Mode" option will appear and you'll be able run it by restarting the device.
[Zurück zum Inhaltsverzeichnis]
Check the battery usage of various applications:

Go to "Settings", scroll down until you see "Device maintenance" and tap it.

Tap "Battery" and check the usage of each application. Legitimate/genuine applications are designed to use as low energy as possible in order to provide the best user experience and to save power. Therefore, high battery usage may indicate that the application is malicious.
[Zurück zum Inhaltsverzeichnis]
Check the data usage of various applications:

Go to "Settings", scroll down until you see "Connections" and tap it.

Scroll down until you see "Data usage" and select this option. As with battery, legitimate/genuine applications are designed to minimize data usage as much as possible. This means that huge data usage may indicate presence of malicious application. Note that some malicious applications might be designed to operate when the device is connected to wireless network only. For this reason, you should check both Mobile and Wi-Fi data usage.

If you find an application that uses a lot of data even though you never use it, then we strongly advise you to uninstall it as soon as possible.
[Zurück zum Inhaltsverzeichnis]
Install the latest software updates:
Keeping the software up-to-date is a good practice when it comes to device safety. The device manufacturers are continually releasing various security patches and Android updates in order to fix errors and bugs that can be abused by cybercriminals. An outdated system is way more vulnerable, which is why you should always be sure that your device's software is up-to-date.

Go to "Settings", scroll down until you see "Software update" and tap it.

Tap "Download updates manually" and check if there are any updates available. If so, install them immediately. We also recommend to enable the "Download updates automatically" option - it will enable the system to notify you once an update is released and/or install it automatically.
[Zurück zum Inhaltsverzeichnis]
Reset the system to its default state:
Performing a "Factory Reset" is a good way to remove all unwanted applications, restore system's settings to default and clean the device in general. However, you must keep in mind that all data within the device will be deleted, including photos, video/audio files, phone numbers (stored within the device, not the SIM card), SMS messages, and so forth. In other words, the device will be restored to its primal state.
You can also restore the basic system settings and/or simply network settings as well.

Go to "Settings", scroll down until you see "About phone" and tap it.

Scroll down until you see "Reset" and tap it. Now choose the action you want to perform:
"Reset settings" - restore all system settings to default;
"Reset network settings" - restore all network-related settings to default;
"Factory data reset" - reset the entire system and completely delete all stored data;
[Zurück zum Inhaltsverzeichnis]
Disable applications that have administrator privileges:
If a malicious application gets administrator-level privileges it can seriously damage the system. To keep the device as safe as possible you should always check what apps have such privileges and disable the ones that shouldn't.

Go to "Settings", scroll down until you see "Lock screen and security" and tap it.

Scroll down until you see "Other security settings", tap it and then tap "Device admin apps".

Identify applications that should not have administrator privileges, tap them and then tap "DEACTIVATE".
Frequently Asked Questions (FAQ)
My Android device is infected with Mantax Otax malware, should I format my storage device to get rid of it?
Formatting is usually not needed to remove Mantax Otax. Running a reputable mobile antivirus such as Combo Cleaner should be enough to detect and eliminate it. Keep in mind that removing the malware (or formatting the device) will not decrypt files that have already been locked, so restore them from a backup if you have one.
What are the biggest issues that Mantax Otax malware can cause?
Mantax Otax can encrypt photos and documents, lock the phone behind fake lock screens, and steal the real lock screen PIN. It also records the screen, takes secret photos, and collects SMS messages (including one-time passwords), contacts, call logs, browser history, and WhatsApp and Telegram chats.
As a result, victims face data loss, serious privacy issues, financial losses, and identity theft.
What is the purpose of Mantax Otax malware?
Most malware attacks are driven by profit, and Mantax Otax is no exception - it pressures victims into paying to get their files back while harvesting data that can be abused or sold. That said, malware can also be used for amusement, personal grudges, disruption, hacktivism, or political reasons, and the harassment features in the second version suggest some operators simply enjoy tormenting victims.
How did Mantax Otax malware infiltrate my Android device?
Mantax Otax has been spread as APK files on third-party file-sharing services, with links pushed through messaging apps, phishing messages, and other social engineering. The samples seen so far posed as an Indonesian adult-content app or as legitimate apps like Grok. It is not distributed through the Google Play Store, so victims have to install it manually.
Will Combo Cleaner protect me from malware?
Combo Cleaner is capable of detecting and eliminating nearly all known malware infections, including threats like Mantax Otax. Performing a complete system scan is essential, since sophisticated malicious programs typically hide deep within the system.
Teilen:
Tomas Meskauskas
Erfahrener Sicherheitsforscher, professioneller Malware-Analyst
Meine Leidenschaft gilt der Computersicherheit und -technologie. Ich habe mehr als 10 Jahre Erfahrung in verschiedenen Unternehmen im Zusammenhang mit der Lösung computertechnischer Probleme und der Internetsicherheit. Seit 2010 arbeite ich als Autor und Redakteur für PCrisk. Folgen Sie mir auf Twitter und LinkedIn, um über die neuesten Bedrohungen der Online-Sicherheit informiert zu bleiben.
Das Sicherheitsportal PCrisk wird von der Firma RCS LT bereitgestellt.
Gemeinsam klären Sicherheitsforscher Computerbenutzer über die neuesten Online-Sicherheitsbedrohungen auf. Weitere Informationen über das Unternehmen RCS LT.
Unsere Anleitungen zur Entfernung von Malware sind kostenlos. Wenn Sie uns jedoch unterstützen möchten, können Sie uns eine Spende schicken.
SpendenDas Sicherheitsportal PCrisk wird von der Firma RCS LT bereitgestellt.
Gemeinsam klären Sicherheitsforscher Computerbenutzer über die neuesten Online-Sicherheitsbedrohungen auf. Weitere Informationen über das Unternehmen RCS LT.
Unsere Anleitungen zur Entfernung von Malware sind kostenlos. Wenn Sie uns jedoch unterstützen möchten, können Sie uns eine Spende schicken.
Spenden
▼ Diskussion einblenden