Android Mantax Otax Ransomware Steals OTPs and Takes Photos
A newly discovered Android malware named Mantax Otax combines ransomware with spyware capabilities. The threat can encrypt files, monitor screens, steal SMS-based OTPs, capture lock-screen PINs, and secretly take photos using the device’s cameras.


The malware is reportedly distributed through malicious APK files hosted on third-party file-sharing platforms. Victims may be tricked into installing these apps through phishing messages, social media posts, or unfamiliar links. Once installed, Mantax Otax abuses permissions such as Accessibility, SMS, device administrator, camera, and screen recording.
The ransomware can also collect contacts, call logs, browser history, location data, WhatsApp and Telegram information, and device details. Its ability to steal verification codes and credentials increases the risk of account takeover, identity theft, and financial fraud. Users should avoid sideloading apps, review permissions carefully, and install applications only from trusted sources.
NPAV Endpoint Security, help detect fileless malware, block malicious scripts, and protect users from credential-stealing attacks delivered through fake software downloads.