A newly documented strain of Android malware is blurring the line between ransomware and spyware, and it's doing so in a way that directly threatens one of the most common security safeguards people rely on: one-time passcodes (OTPs). Dubbed Mantax Otax, the malware doesn't just lock up a victim's files and demand payment. It also watches what's happening on the screen, quietly activates the camera, and intercepts verification codes sent to the device, giving attackers a far more complete picture of a victim's digital life than typical ransomware ever could.
What Mantax Otax Does: Ransomware and Spyware Combined
Most mobile ransomware follows a familiar playbook: encrypt files or lock the device, then display a ransom note demanding payment to restore access. Mantax Otax builds on that foundation but adds a second layer of malicious behavior that functions independently of whether a victim pays up. According to researchers who identified the malware, it combines file-locking ransomware components with spyware features that let attackers monitor screens, access the camera to take photos without the user's knowledge, and capture one-time passcodes as they arrive on the device.
This dual-purpose design means Mantax Otax isn't just an extortion tool. It's also a surveillance and data-theft platform. Even if a victim refuses to pay the ransom, the attackers may have already collected screen recordings, photos, and authentication codes that can be used for identity theft, account takeover, or further extortion. Reporting on the malware links it to Indonesian threat actors and describes remote-control capabilities that give attackers hands-on access to infected devices, not just automated data collection.
Why OTP Theft and Screen Recording Change the Calculus
One-time passcodes sent via SMS or generated by authenticator apps are supposed to be a safety net, a second layer of defense in case a password is compromised. Mantax Otax undermines that safety net directly. By intercepting OTPs in real time, the malware can potentially hand attackers the exact codes needed to break into banking apps, email accounts, or other services protected by two-factor authentication, even when the underlying password itself was never stolen through traditional phishing.
Screen recording compounds the problem. If attackers can see everything displayed on a victim's phone, they don't need to guess which app is open or what data is visible. They can watch banking sessions, messaging apps, or password managers as the victim uses them. Add in the ability to secretly activate the camera, and Mantax Otax starts to resemble a full surveillance tool wrapped inside a ransomware shell, a combination that raises the stakes well beyond a typical file-locking incident.
How the Malware Likely Spreads and Who's at Risk
Android malware of this type typically spreads through channels outside the official Google Play Store, including sideloaded APK files, phishing links sent via SMS or messaging apps, and fake app listings disguised as legitimate software. Mobile users who install apps from unofficial sources, click links from unknown senders, or grant broad permissions without reviewing them are generally the most exposed to threats like this one.
This pattern fits into a broader trend of increasingly sophisticated mobile-targeted attacks. Mantax Otax arrives amid a steady stream of new malware families exploiting both consumer devices and enterprise infrastructure, a landscape covered in more depth in a recent roundup of emerging malware and vulnerability disclosures, which highlights how attackers are combining multiple techniques, from AI-powered infostealers to industrial exploit chains, into single, more dangerous packages.
What This Means For You
If you use an Android device for banking, messaging, or any account protected by SMS-based two-factor authentication, Mantax Otax is a reminder that OTPs are not an unbreakable shield, especially if the device receiving them is already compromised. The malware's ability to record screens and access the camera also means that infections can expose far more than financial data; personal conversations, photos, and daily habits could all be captured without a victim ever knowing.
The good news is that the primary infection vectors for malware like this remain avoidable. Sticking to official app stores, scrutinizing permission requests, and being skeptical of unsolicited links or app-install prompts go a long way toward preventing infection in the first place.
Actionable Takeaways
- Only install apps from the Google Play Store or other verified, official sources. Avoid sideloading APKs from unfamiliar websites or links.
- Review app permissions carefully, especially requests for camera access, screen recording, or SMS reading, and revoke anything that seems unnecessary for the app's function.
- Consider using authenticator apps rather than SMS-based OTPs where possible, and monitor accounts for unusual login activity.
- Keep your device's operating system and security patches up to date, and run a reputable mobile security scan if you suspect unusual behavior.
- Stay informed about emerging mobile threats. Mantax Otax is part of a wider pattern of hybrid malware, and staying current on how these threats evolve is one of the simplest ways to stay ahead of them.




