Comment supprimer Mantax Otax des appareils Android
de TroieÉgalement connu sous le nom de: Mantax Otax trojan
Obtenez une analyse gratuite et vérifiez si votre ordinateur est infecté.
SUPPRIMEZ-LES MAINTENANTPour utiliser le produit complet, vous devez acheter une licence pour Combo Cleaner. 7 jours d’essai limité gratuit disponible. Combo Cleaner est détenu et exploité par RCS LT, la société mère de PCRisk.
Quel type de malware est Mantax Otax ?
Mantax Otax est un ransomware Android doté de fonctionnalités spyware intégrées, ciblant les utilisateurs en Indonésie. Il chiffre les fichiers présents sur l'appareil, verrouille l'écran et pousse les victimes à engager une conversation avec les attaquants, tout en dérobant discrètement messages, photos, mots de passe et autres données personnelles. Le malware a été analysé pour la première fois par l'équipe zLabs de Zimperium.

Mantax Otax malware overview
Mantax Otax is linked to Indonesian threat actors, and two versions of it have been found so far, with the second building on the first. Language clues and files recovered from victims show that the operators focus on Indonesian users.
Right after installation, the malware asks for device administrator rights. The admin prompt openly lists abilities such as erasing all data, changing the screen lock, locking the screen, and disabling cameras. It then requests access to the camera, SMS messages, contacts, audio, and images, along with permission to display content over other apps.
The last step is a request for Accessibility Services access, shown as an Indonesian-language pop-up that asks the victim to enable both Accessibility and notification access. Once granted, this gives the attackers broad control over the device, including the ability to read what is on the screen and tap on the victim's behalf.
Mantax Otax talks to its command-and-control (C2) server over HTTPS. Instead of storing the server address in its code, it pulls the current domain (apimantax[.]otax[.]fun) from a GitHub repository. This lets the operators move to a new server whenever the old one gets blocked, without having to update the malware itself.
The malware then gives the device a unique ID and registers it with the server. The registration data includes the phone model and manufacturer, Android version, country, mobile carrier, and even whether a lock screen PIN has been set. After that, it waits for commands, which are delivered through Firebase.
For the ransomware part, Mantax Otax requests an encryption key from the C2 server. Each key is tied to the victim's Android ID, so every infected device gets a different one. The malware then looks for photos, videos, documents, archives, databases, and cryptographic key files, locks them with AES encryption, and deletes the originals.
Encrypted files keep their original name with .enc added to the end (for example, sample_image.jpg.enc). Some images are also swapped for altered copies stamped with the message "Your files have been encrypted. Pay to decrypt." In Zimperium's test, gallery thumbnails turned into blank file icons, with one picture replaced by red ransom text.
How much damage this does depends on the Android version. On Android 9 or older, the malware digs through the entire shared storage, skipping only the system folders it needs to leave alone to avoid crashing the phone. Android 10 and newer use a protection called Scoped Storage, which confines the malware to its own app folder and greatly limits the number of files it can reach.
Once encryption is done, a full-screen chat window titled SYSTEM PROTECTED takes over the display, and the attacker appears in it as Mantax Bro!!. This is where victims are told to negotiate a payment. Because the operators misconfigured their Firebase server, Zimperium was able to read these conversations, including messages from victims begging to get their files back.
Combined with the data theft described below, this puts victims in a double-extortion situation, where both their files and their personal information are in the attackers' hands.
Mantax Otax can also lock the phone behind a fake system lock screen. One version reads SYSTEM PROTECTED, claims the device is under an administrative lock, and carries Manta X2 Elite Security branding, while another is written in Indonesian. Both ask for a PIN, so victims end up handing their real lock screen code straight to the attackers.
The spyware side is just as broad. By abusing Android's built-in screen recording feature (the MediaProjection API), the malware can take screenshots, record the screen as MP4 videos, and stream the display live to the attackers. Screenshots and recordings are uploaded to the free file host Catbox, and the download links are sent to the operators.
On top of that, Mantax Otax collects contacts, call logs, incoming SMS messages (including one-time passwords used for logins), notifications, browser history, installed apps, location, linked Google accounts, files, and gallery photos. Through Accessibility Services, it also steals WhatsApp profiles and messages, as well as Telegram account details and chats, by opening conversations on its own and copying their contents.
The malware can secretly take photos with the front or rear camera, with no visible sign on the screen. The photos are compressed, encoded in Base64, and sent to the operators - leaked server records show them being stored on Catbox as well.
Files exposed by the misconfigured server also included a screenshot of the operators' control panel, branded Manta Controller. At the time, it listed 210 infected devices (only two of them online), including phones from vivo, Infinix, and Xiaomi.
The second version switches to WebSocket connections through another subdomain (apixnxx[.]otax[.]fun) and adds new commands aimed at controlling and tormenting victims. It can lock the screen with an Indonesian-language message claiming that the device is controlled by Manta X2, that all activity is being watched, and that the victim must contact an admin to regain access.
Version 2 can also block individual apps and place an invisible layer over the entire screen that swallows every tap and swipe, leaving the phone visible but unusable. Other commands flood the display with pop-up dialogs, play a full-screen video to hide what is happening in the background, or flash scary images every 600 milliseconds to create a disorienting strobe effect.
The operators can even make the phone talk. A remote text-to-speech command reads out any message the attackers choose through the device speaker, with adjustable language, speed, and pitch.
In summary, the presence of software like Mantax Otax on devices can lead to multiple system infections, serious privacy issues, financial losses, and identity theft. Victims risk losing their photos and documents, their accounts, and their private conversations all at once.
It has to be mentioned that malware developers often improve upon their software and methodologies. Hence, potential future iterations of Mantax Otax could have additional or different functionalities and features.
| Name | Mantax Otax trojan |
| Threat Type | Android malware, malicious application, ransomware, spyware, unwanted application. |
| Detection Names | Avast-Mobile (Android:Evo-gen [Trj]), Combo Cleaner (Android.Riskware.SpyAgent.OV), ESET-NOD32 (Android/Spy.Agent.GGC Trojan), Kaspersky (HEUR:Backdoor.AndroidOS.Agent.iz), Full List (VirusTotal) |
| Symptoms | Files are encrypted and renamed with the .enc extension, the screen is locked by a fake system lock or chat window, the device is running slow, data and battery usage is increased significantly, questionable applications appear, pop-ups and overlays block normal use. |
| Distribution methods | APK files on third-party file-sharing services, links shared via messaging apps, phishing messages, social engineering, apps disguised as legitimate or adult-content applications. |
| Damage | Encrypted files, locked device, stolen personal information (private messages, logins/passwords, one-time passwords, photos, etc.), decreased device performance, battery is drained quickly, decreased Internet speed, huge data losses, monetary losses, stolen identity (malicious apps might abuse communication apps). |
|
Suppression des maliciels (Windows) |
Pour éliminer d'éventuelles infections par des maliciels, analysez votre ordinateur avec un logiciel antivirus légitime. Nos chercheurs en sécurité recommandent d'utiliser Combo Cleaner. Téléchargez Combo CleanerUn scanner gratuit vérifie si votre ordinateur est infecté. Pour utiliser le produit complet, vous devez acheter une licence pour Combo Cleaner. 7 jours d’essai limité gratuit disponible. Combo Cleaner est détenu et exploité par RCS LT, la société mère de PCRisk. |
Conclusion
Mantax Otax is a nasty combination of ransomware and spyware. It can lock a victim out of their phone and files, pressure them into paying through a chat window, and at the same time collect nearly everything stored on or shown by the device. Even if files are recovered, the stolen messages, codes, and photos remain a long-term risk.
Other examples of Android-specific malware include Manic, WindRelay, and Rokarolla. Malicious apps like these tend to request extensive permissions and abuse them to steal data, spy on users, or take over the device entirely.
How did Mantax Otax infiltrate my device?
Zimperium found Mantax Otax samples hosted as APK files on a third-party file-sharing service, where one of them was offered under the name VoCNewEra. Links to such files are usually spread through messaging apps, phishing messages, and other social engineering tricks. Since the app is not on the Google Play Store, victims have to manually allow its installation.
The lures seen so far include an app with an Indonesian name hinting at adult content, and some samples reportedly pose as legitimate apps such as Grok. Cybercriminals rely on disguises like these because curious or trusting users are more likely to tap through the long list of permission requests without thinking twice.
How to avoid installation of malware?
Install apps only from the Google Play Store or the developer's official website, and be wary of APK files shared through file-hosting links, chats, or social media - even when a friend sends them. Pay attention to the permissions an app asks for. A video player, chatbot, or game has no reason to need administrator rights, Accessibility Services, or the ability to read your SMS messages.
Keep Android and your apps updated, since newer Android versions limit what malware like this can reach. Ignore unexpected messages that push you to download something, and avoid adult, cracked, or "premium for free" apps from unofficial sources. It also helps to have a reputable mobile antivirus installed and to back up important photos and documents regularly.
Mantax Otax APK hosted on a third-party file-sharing website (source: zimperium.com):

Permission requests displayed by Mantax Otax during installation (source: zimperium.com):

Files on an infected device before and after Mantax Otax encryption (source: zimperium.com):

Fake lock screens used by Mantax Otax to steal the victim's PIN (source: zimperium.com):

Screen-blocking message shown by the second version of Mantax Otax (source: zimperium.com):

Quick menu:
- Introduction
- How to delete browsing history from the Chrome web browser?
- How to disable browser notifications in the Chrome web browser?
- How to reset the Chrome web browser?
- How to delete browsing history from the Firefox web browser?
- How to disable browser notifications in the Firefox web browser?
- How to reset the Firefox web browser?
- How to uninstall potentially unwanted and/or malicious applications?
- How to boot the Android device in "Safe Mode"?
- How to check the battery usage of various applications?
- How to check the data usage of various applications?
- How to install the latest software updates?
- How to reset the system to its default state?
- How to disable applications that have administrator privileges?
Delete browsing history from the Chrome web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "History" in the opened dropdown menu.

Tap "Clear browsing data", select "ADVANCED" tab, choose the time range and data types you want to delete and tap "Clear data".
[Retour à la Table des Matières]
Disable browser notifications in the Chrome web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "Settings" in the opened dropdown menu.

Scroll down until you see "Site settings" option and tap it. Scroll down until you see "Notifications" option and tap it.

Find the websites that deliver browser notifications, tap on them and click "Clear & reset". This will remove permissions granted for these websites to deliver notifications. However, once you visit the same site again, it may ask for a permission again. You can choose whether to give these permissions or not (if you choose to decline the website will go to "Blocked" section and will no longer ask you for the permission).
[Retour à la Table des Matières]
Reset the Chrome web browser:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you find "Chrome" application, select it and tap "Storage" option.

Tap "MANAGE STORAGE", then "CLEAR ALL DATA" and confirm the action by taping "OK". Note that resetting the browser will eliminate all data stored within. This means that all saved logins/passwords, browsing history, non-default settings and other data will be deleted. You will also have to re-login into all websites as well.
[Retour à la Table des Matières]
Delete browsing history from the Firefox web browser:

Tap the "Menu" button (three dots on the right-upper corner of the screen) and select "History" in the opened dropdown menu.

Scroll down until you see "Clear private data" and tap it. Select data types you want to remove and tap "CLEAR DATA".
[Retour à la Table des Matières]
Disable browser notifications in the Firefox web browser:

Visit the website that is delivering browser notifications, tap the icon displayed on the left of URL bar (the icon will not necessarily be a "Lock") and select "Edit Site Settings".

In the opened pop-up opt-in the "Notifications" option and tap "CLEAR".
[Retour à la Table des Matières]
Reset the Firefox web browser:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you find "Firefox" application, select it and tap "Storage" option.

Tap "CLEAR DATA" and confirm the action by taping "DELETE". Note that resetting the browser will eliminate all data stored within. This means that all saved logins/passwords, browsing history, non-default settings and other data will be deleted. You will also have to re-login into all websites as well.
[Retour à la Table des Matières]
Uninstall potentially unwanted and/or malicious applications:

Go to "Settings", scroll down until you see "Apps" and tap it.

Scroll down until you see a potentially unwanted and/or malicious application, select it and tap "Uninstall". If, for some reason, you are unable to remove the selected app (e.g., you are prompted with an error message), you should try using the "Safe Mode".
[Retour à la Table des Matières]
Boot the Android device in "Safe Mode":
The "Safe Mode" in Android operating system temporarily disables all third-party applications from running. Using this mode is a good way to diagnose and solve various issues (e.g., remove malicious applications that prevent users you from doing so when the device is running "normally").

Push the "Power" button and hold it until you see the "Power off" screen. Tap the "Power off" icon and hold it. After a few seconds the "Safe Mode" option will appear and you'll be able run it by restarting the device.
[Retour à la Table des Matières]
Check the battery usage of various applications:

Go to "Settings", scroll down until you see "Device maintenance" and tap it.

Tap "Battery" and check the usage of each application. Legitimate/genuine applications are designed to use as low energy as possible in order to provide the best user experience and to save power. Therefore, high battery usage may indicate that the application is malicious.
[Retour à la Table des Matières]
Check the data usage of various applications:

Go to "Settings", scroll down until you see "Connections" and tap it.

Scroll down until you see "Data usage" and select this option. As with battery, legitimate/genuine applications are designed to minimize data usage as much as possible. This means that huge data usage may indicate presence of malicious application. Note that some malicious applications might be designed to operate when the device is connected to wireless network only. For this reason, you should check both Mobile and Wi-Fi data usage.

If you find an application that uses a lot of data even though you never use it, then we strongly advise you to uninstall it as soon as possible.
[Retour à la Table des Matières]
Install the latest software updates:
Keeping the software up-to-date is a good practice when it comes to device safety. The device manufacturers are continually releasing various security patches and Android updates in order to fix errors and bugs that can be abused by cybercriminals. An outdated system is way more vulnerable, which is why you should always be sure that your device's software is up-to-date.

Go to "Settings", scroll down until you see "Software update" and tap it.

Tap "Download updates manually" and check if there are any updates available. If so, install them immediately. We also recommend to enable the "Download updates automatically" option - it will enable the system to notify you once an update is released and/or install it automatically.
[Retour à la Table des Matières]
Reset the system to its default state:
Performing a "Factory Reset" is a good way to remove all unwanted applications, restore system's settings to default and clean the device in general. However, you must keep in mind that all data within the device will be deleted, including photos, video/audio files, phone numbers (stored within the device, not the SIM card), SMS messages, and so forth. In other words, the device will be restored to its primal state.
You can also restore the basic system settings and/or simply network settings as well.

Go to "Settings", scroll down until you see "About phone" and tap it.

Scroll down until you see "Reset" and tap it. Now choose the action you want to perform:
"Reset settings" - restore all system settings to default;
"Reset network settings" - restore all network-related settings to default;
"Factory data reset" - reset the entire system and completely delete all stored data;
[Retour à la Table des Matières]
Disable applications that have administrator privileges:
If a malicious application gets administrator-level privileges it can seriously damage the system. To keep the device as safe as possible you should always check what apps have such privileges and disable the ones that shouldn't.

Go to "Settings", scroll down until you see "Lock screen and security" and tap it.

Scroll down until you see "Other security settings", tap it and then tap "Device admin apps".

Identify applications that should not have administrator privileges, tap them and then tap "DEACTIVATE".
Frequently Asked Questions (FAQ)
My Android device is infected with Mantax Otax malware, should I format my storage device to get rid of it?
Formatting is usually not needed to remove Mantax Otax. Running a reputable mobile antivirus such as Combo Cleaner should be enough to detect and eliminate it. Keep in mind that removing the malware (or formatting the device) will not decrypt files that have already been locked, so restore them from a backup if you have one.
What are the biggest issues that Mantax Otax malware can cause?
Mantax Otax can encrypt photos and documents, lock the phone behind fake lock screens, and steal the real lock screen PIN. It also records the screen, takes secret photos, and collects SMS messages (including one-time passwords), contacts, call logs, browser history, and WhatsApp and Telegram chats.
As a result, victims face data loss, serious privacy issues, financial losses, and identity theft.
What is the purpose of Mantax Otax malware?
Most malware attacks are driven by profit, and Mantax Otax is no exception - it pressures victims into paying to get their files back while harvesting data that can be abused or sold. That said, malware can also be used for amusement, personal grudges, disruption, hacktivism, or political reasons, and the harassment features in the second version suggest some operators simply enjoy tormenting victims.
How did Mantax Otax malware infiltrate my Android device?
Mantax Otax has been spread as APK files on third-party file-sharing services, with links pushed through messaging apps, phishing messages, and other social engineering. The samples seen so far posed as an Indonesian adult-content app or as legitimate apps like Grok. It is not distributed through the Google Play Store, so victims have to install it manually.
Will Combo Cleaner protect me from malware?
Combo Cleaner is capable of detecting and eliminating nearly all known malware infections, including threats like Mantax Otax. Performing a complete system scan is essential, since sophisticated malicious programs typically hide deep within the system.
Partager:
Tomas Meskauskas
Chercheur expert en sécurité, analyste professionnel en logiciels malveillants
Je suis passionné par la sécurité informatique et la technologie. J'ai une expérience de plus de 10 ans dans diverses entreprises liées à la résolution de problèmes techniques informatiques et à la sécurité Internet. Je travaille comme auteur et éditeur pour PCrisk depuis 2010. Suivez-moi sur Twitter et LinkedIn pour rester informé des dernières menaces de sécurité en ligne.
Le portail de sécurité PCrisk est proposé par la société RCS LT.
Des chercheurs en sécurité ont uni leurs forces pour sensibiliser les utilisateurs d'ordinateurs aux dernières menaces en matière de sécurité en ligne. Plus d'informations sur la société RCS LT.
Nos guides de suppression des logiciels malveillants sont gratuits. Cependant, si vous souhaitez nous soutenir, vous pouvez nous envoyer un don.
Faire un donLe portail de sécurité PCrisk est proposé par la société RCS LT.
Des chercheurs en sécurité ont uni leurs forces pour sensibiliser les utilisateurs d'ordinateurs aux dernières menaces en matière de sécurité en ligne. Plus d'informations sur la société RCS LT.
Nos guides de suppression des logiciels malveillants sont gratuits. Cependant, si vous souhaitez nous soutenir, vous pouvez nous envoyer un don.
Faire un don
▼ Montrer la discussion