Mantax OTAX Android malware steals OTPs and encrypts files

Published September 11, 2026

Mantax OTAX is a dangerous Android malware that steals one-time passwords, spies on users, and locks their files for ransom. It spreads through fake apps downloaded outside Google Play.

Report priority
High
Involves
Android

What is known

  • Attackers send fake Android apps outside Google Play that trick users into installing them.
  • Once installed, the malware steals one-time passwords from banking apps, records calls and messages, and locks files for ransom.
  • It also lets attackers control the infected phone remotely.

What to do

If you installed an Android app from anywhere other than Google Play, check for unusual behavior like locked files, unexpected calls being recorded, or messages disappearing. Look for apps you don't recognize in your downloads or app list.

Uninstall any suspicious apps immediately. Restore files from a backup if available. Do not pay the ransom. Report the incident to your bank and Android's security team if you suspect your device is infected.

Reported details

A user downloads a fake banking app from a third-party site. After installing it, the malware steals their OTPs, records their calls, and encrypts their files, then demands payment to unlock them.

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion.