New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

By Published On: September 12, 2026

A disturbing new threat has emerged on the Android landscape, blurring the lines between ransomware and sophisticated espionage. This isn’t just about locking your files; it’s about a complete compromise of your digital privacy and financial security. We’re talking about a multi-faceted attack that holds your data hostage while simultaneously watching your every move, stealing critical verification codes, and even taking secret photos without your knowledge. This advanced threat highlights the critical importance of secure mobile practices in an increasingly hostile digital environment.

Mantax Otax: The Blended Threat Explained

Dubbed Mantax Otax, this Android malware represents a significant escalation in mobile device attacks. Unlike traditional ransomware that merely encrypts files and demands a ransom, Mantax Otax integrates a robust spying component, turning a single infection into both an extortion and a profound privacy crisis. The campaign specifically targets users who install applications from untrusted links, a common vector for mobile malware distribution.

Here’s a breakdown of its alarming capabilities:

  • File Encryption and Device Locking: Standard ransomware functionality, rendering your personal files inaccessible and potentially locking your entire device.
  • Screen Recording: Mantax Otax can covertly record your screen activity, capturing sensitive information like passwords, financial details, and private conversations as you interact with your device.
  • One-Time Password (OTP) Interception: A critical security bypass, the malware is designed to intercept OTPs and verification codes, allowing attackers to circumvent two-factor authentication (2FA) and gain unauthorized access to banking apps, email accounts, and other sensitive services.
  • Covert Photo Capture: Perhaps the most unnerving feature, Mantax Otax can secretly activate your phone’s cameras to take photos of the victim and their surroundings without any indication. This capability raises significant concerns about personal privacy and potential blackmail.

This blended attack profile makes Mantax Otax particularly dangerous, as it offers attackers multiple avenues for exploitation, from financial gain through ransomware to identity theft and personal harassment via stolen information and imagery.

Understanding the Attack Vector

The primary infection vector for Mantax Otax appears to be malicious applications distributed through untrusted links. These links are often found in phishing emails, deceptive social media posts, or third-party app stores. Users, lured by the promise of free or unique applications, download and install these malicious packages, unwittingly granting Mantax Otax the necessary permissions to execute its harmful functions.

Once installed, the malware typically requests broad permissions, often disguised as legitimate functionalities. Granting these permissions allows Mantax Otax to:

  • Access storage for file encryption.
  • Overlay content on other apps to record screen activity.
  • Read SMS messages to intercept OTPs.
  • Access the camera for covert photography.

Remediation Actions and Prevention

Protecting yourself from sophisticated threats like Mantax Otax requires a proactive and informed approach to mobile security. Here are essential remediation actions and preventative measures:

  • Avoid Untrusted Sources: Only download applications from official and reputable sources like the Google Play Store. Exercise extreme caution with third-party app stores or direct download links.
  • Scrutinize App Permissions: Before installing any app, carefully review the requested permissions. Be suspicious of apps asking for excessive or irrelevant permissions (e.g., a simple game requesting camera or SMS access).
  • Regular Backups: Maintain regular backups of all critical data to a secure, off-device location. This mitigates the impact of ransomware encryption, allowing you to restore your files without paying a ransom.
  • Keep Software Updated: Ensure your Android operating system and all installed applications are kept up-to-date. Software updates often include patches for known vulnerabilities that malware might exploit.
  • Install a Reputable Mobile Security Solution: Utilize a trusted mobile antivirus or security app that can detect and block malicious applications and monitor for suspicious activity.
  • Enable Two-Factor Authentication (2FA): While Mantax Otax can intercept OTPs, 2FA still provides an additional layer of security. Use app-based authenticators (like Google Authenticator) or hardware keys when available, as they are generally more resilient to SMS interception.
  • Be Wary of Phishing: Remain vigilant against phishing attempts. Do not click on suspicious links in emails, text messages, or social media, even if they appear to come from a known contact.
  • Revoke Unnecessary Permissions: Periodically review the permissions granted to your installed applications and revoke any that are not essential for the app’s functionality.

Tools for Detection and Mitigation

Employing the right tools can significantly enhance your mobile security posture against threats like Mantax Otax.

Tool Name Purpose Link
Google Play Protect Built-in Android security for app scanning. Google Play Protect Info
Malwarebytes Security for Android Detects and removes malware, ransomware, and phishing. Malwarebytes Mobile
Avast Mobile Security Comprehensive mobile security, including antivirus and app lock. Avast Android
Bitdefender Mobile Security Advanced threat detection, anti-theft, and VPN. Bitdefender Android
Authy / Google Authenticator App-based 2FA for enhanced account security. Authy / Google Authenticator

The Evolving Threat Landscape

The emergence of Mantax Otax serves as a stark reminder of the sophisticated and evolving nature of mobile malware. Attackers are increasingly combining different malicious functionalities to maximize their impact and profit. This trend necessitates a heightened sense of vigilance from users and a commitment to robust security practices. The days of simply worrying about data theft are long gone; now, our physical privacy, financial stability, and even personal safety can be directly threatened by a single, malicious application.

Staying informed about new threats, adhering to best security practices, and utilizing reputable security tools are paramount to safeguarding your digital life against these complex, multi-layered attacks.

Share this article

Leave A Comment