Mantax Otax is the Android malware that encrypts your files, steals your messages, and then harasses you

Most malware picks a lane. Mantax Otax did not. Security researchers at Zimperium have identified a new Android malware that can encrypt your files, pull private messages from WhatsApp and Telegram, record your screen, and then spam you into paying a ransom. All in one package. As reported by Android Headlines, this is not a theoretical risk buried in a lab report. It is an active threat with real capabilities.

The malware spreads through malicious APKs distributed outside of Google Play. Once installed, it requests access to Android’s Accessibility service, the system feature designed to help users with disabilities by enabling screen reading and automated gestures. Granting that permission hands the malware deep control over the device. From there, it retrieves its command-and-control domain from GitHub, then phones home with the victim’s location, mobile carrier, Android version, and device ID.

The file encryption component uses victim-specific AES keys and replaces local images with ransom notices. But Mantax Otax goes further than most ransomware. It can extract message histories from WhatsApp and Telegram, capture screenshots, record video, and live-stream the victim’s screen back to the attackers. The harassment element, actively pressuring victims to pay, makes this feel less like automated crime and more like a targeted campaign designed to break people down.

There is some limited good news. The encryption capability works reliably only on Android 9 and older, according to Zimperium’s findings. If you are running a recent version of Android, the ransomware side of this is less likely to fully execute. But the spyware functions, screen recording, message extraction, and remote surveillance, are not limited by OS version in the same way. So running a newer Android does not make you safe. It just makes part of the attack harder to complete.

Protecting yourself comes down to a few straightforward habits:

  • Keep your Android version up to date. Older versions face a much higher risk from the encryption component.
  • Do not sideload APKs from unknown sources. If someone sends you an APK through email or a messaging app, ignore it.
  • Stay away from sites offering cracked or modded apps. These are a common delivery method for exactly this kind of malware.
  • If you need apps outside the Play Store, stick to sources like APKMirror or F-Droid, which have review processes in place.

The bigger issue here is the combination of attack types. Ransomware alone is damaging. Spyware alone is serious. Bundling them together with an active harassment layer raises the stakes considerably. It also fits a pattern researchers have been tracking for a while now, where mobile malware is becoming more sophisticated and more aggressive, targeting the personal and financial data that lives on our phones rather than on laptops or desktops.

Android’s open ecosystem is genuinely useful. But that openness, specifically the ability to install apps from outside the Play Store, is also the primary attack surface this malware exploits. That’s a tension Google has never fully resolved, and Mantax Otax is another reminder of what the cost of that openness can look like in practice.