Back to Intelligence

Mantax Otax Mobile Ransomware + NEBULA npm Supply-Chain RAT: OTX Pulse Analysis — Cross-Platform Detection Pack

SA
Security Arsenal Team
October 10, 2026
10 min read

Two fresh AlienVault OTX pulses — published October 9–10, 2026 — expose concurrent offensive operations hitting both mobile and developer ecosystems. The first, Mantax Otax, is an Indonesian Android ransomware with fully integrated spyware capabilities, attributed by Zimperium to Indonesian actors and tagged with the ToxicPanda family. The second, NEBULA, is a supply-chain operation that deployed seven malicious npm packages masquerading as a "NebulaAI" SDK to deliver a Windows remote-access trojan (KNTRAT) with HVNC (Hidden Virtual Network Computing) capability.

Neither campaign has confirmed attribution, and both rely on social engineering against high-trust channels — third-party file-sharing platforms for mobile users, and the npm registry for developers. Enterprise teams face a dual-surface problem: personal and BYOD devices used by Indonesian users, and developer workstations or CI/CD pipelines that may have installed poisoned AI SDK packages.


Threat Summary

Pulse 1 — Mantax Otax (Modified 2026-10-10): A mobile threat distributed through third-party file-sharing platforms via social engineering lures. Once installed, the Android payload requests device administrator, SMS, contacts, and accessibility permissions, then encrypts device files using AES. The ransomware component is augmented with spyware: SMS interception, contact exfiltration, and accessibility abuse allow both surveillance and lateral social-engineering propagation. Command-and-control rides on Firebase — Google's legitimate mobile backend infrastructure — which blinds traditional domain-block detection and makes the C2 traffic look like ordinary app telemetry. Over 400 file-hash indicators were published with the pulse.

Pulse 2 — NEBULA (Modified 2026-10-09): In late September 2026, an actor published seven malicious npm packages across four sequential burner accounts (nebulallms through nebulallms4). Packages api-nebula and llm-nebula remained downloadable at publication time. Each package presents a convincing AI client facade while concealing an obfuscated payload that installs KNTRAT, a Windows RAT that "needs no DLL" — implying reflective, fileless, or self-contained injection techniques that reduce on-disk artifacts. HVNC tags indicate the RAT supports hidden desktop sessions for interactive operator access, enabling hands-on-keyboard fraud and credential theft invisible to the legitimate user.

Collective picture: Both operations exploit trusted distribution channels and abuse legitimate infrastructure (npm registry, Firebase) to defeat perimeter controls. The mobile campaign targets end users in Indonesia for financial extortion and data theft; the supply-chain campaign targets developers and, by extension, any organization whose software build chain consumes the tainted packages.


Threat Actor / Malware Profile

Mantax Otax (Android Ransomware + Spyware, ToxicPanda-linked)

  • Attribution: Unknown actor; operationally linked to Indonesian threat actors per Zimperium research.
  • Distribution: Social engineering via third-party file-sharing platforms; sideloaded APKs.
  • Payload behavior: AES file encryption on the device (ransomware), plus SMS harvesting, contact list theft, and surveillance functions (spyware).
  • Permissions requested: Device administrator, SMS, contacts, accessibility services — a classic Android abuse quartet enabling persistence, interception, and UI overlay fraud.
  • C2 communication: Firebase C2 — leveraging Google's cloud messaging/database infrastructure, which is whitelisted by default in most egress policies.
  • Persistence: Device administrator privilege prevents uninstall; accessibility access allows self-protection and permission re-granting.

KNTRAT (Windows RAT, delivered via NEBULA npm packages)

  • Attribution: Unknown. Infrastructure includes api.nebulaai.dev and IPv4 65.87.7.132.
  • Distribution: Seven typosquatted/impersonating npm packages (api-nebula, llm-nebula, others) published from burner accounts nebulallms–nebulallms4. A second indicator, fact-register.md, suggests lure or staging content in the package metadata.
  • Payload behavior: Obfuscated JavaScript in the package delivers a Windows RAT. The "needs no DLL" design indicates in-memory execution or a monolithic PE, minimizing static artifacts.
  • C2 communication: HTTPS to https://api.nebulaai.dev/v2 and hard IP 65.87.7.132, mimicking legitimate AI API traffic.
  • Persistence: Not explicitly listed in the pulse; KNTRAT-class RATs typically use Run keys, scheduled tasks, or service installation — hunt accordingly.
  • Capabilities: HVNC hidden-desktop sessions for covert interactive access; likely credential harvesting and screen capture.

IOC Analysis

Indicator types present:

TypeCountExamplesOperationalization
FileHash-MD5/SHA1/SHA256~40283df0b5583e5f5a282bc0987e220166f0367288b069146ae7d44f4a2d4b21d22Bulk-load into EDR blocklists and VirusTotal Enterprise retrohunts. SHA256 is the primary pivot; MD5/SHA1 are legacy duplicates of the same samples.
IPv4165.87.7.132Block at firewall/proxy; add to threat intel platform watchlist with 90-day TTL. Retro-search NetFlow/proxy logs for 30 days.
Hostname/Domain2api.nebulaai.dev, fact-register.mdDNS sinkhole/block. Hunt DNS query logs across all endpoints and CI runners. Note fact-register.md may be a lure document name — hunt for it in npm cache and download artifacts.
URL1https://api.nebulaai.dev/v2Proxy block; hunt web logs for the full path — the /v2 path narrows false positives versus domain-only matching.

Firebase C2 caveat: Mantax Otax's C2 is not directly enumerable in the IOC set because it rides on legitimate Firebase domains. Detection must shift to behavior: APKs requesting the admin+SMS+accessibility permission combination, and unexpected Firebase traffic from non-whitelisted apps.

Tooling: Ingest the pulse via the OTX DirectConnect API into your TIP (OpenCTI, MISP, ThreatConnect). Use otx pulsedump or the AlienVault SDK to export indicators to STIX/CSV. For hash triage, cross-reference against MalwareBazaar and VT; for the npm packages, audit package-lock.json / yarn.lock files across repositories for nebula-prefixed dependencies.


Detection Engineering

YAML
---
title: NEBULA Malicious npm Package Install Spawning Windows Payload
id: 8f3a2b11-4c6e-4d2a-9b5e-1a7c9e2f3d01
status: experimental
description: Detects node/npm processes spawning script interpreters or executables consistent with KNTRAT delivery from malicious NebulaAI npm packages (api-nebula, llm-nebula).
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent:
        ParentImage|endswith:
            - '\node.exe'
            - '\npm.cmd'
            - '\npm.exe'
            - '\cmd.exe'
    selection_child:
        Image|endswith:
            - '\powershell.exe'
            - '\wscript.exe'
            - '\cscript.exe'
            - '\mshta.exe'
            - '\rundll32.exe'
            - '\regsvr32.exe'
    filter_npm_scripts:
        CommandLine|contains:
            - 'npm run'
            - 'npm test'
    condition: selection_parent and selection_child and not filter_npm_scripts
falsepositives:
    - Legitimate npm install scripts invoking build tooling
level: high
tags:
    - attack.initial_access
    - attack.t1195.002
    - attack.execution
---
title: KNTRAT C2 Communication to NebulaAI Infrastructure
id: 2b7d4c55-9e1f-4a3b-8c6d-5f2a8b1e4d02
status: experimental
description: Detects network connections to KNTRAT command-and-control infrastructure identified in OTX NEBULA pulse.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf
logsource:
    category: network_connection
    product: windows
detection:
    selection_domain:
        DestinationHostname|contains:
            - 'nebulaai.dev'
    selection_ip:
        DestinationIp:
            - '65.87.7.132'
    condition: selection_domain or selection_ip
falsepositives:
    - None expected; domain is actor-controlled
level: critical
tags:
    - attack.command_and_control
    - attack.t1071.001
---
title: Android Ransomware Permission Abuse Pattern - Mantax Otax
id: 5c1e8f33-7a2d-4b4c-9d8e-3f6a1b2c5d03
status: experimental
description: Detects installation of APKs requesting the device administrator, SMS, contacts, and accessibility permission combination characteristic of Mantax Otax mobile ransomware. Deploy via MDM/mobile EDR telemetry forwarded to SIEM.
author: Security Arsenal Threat Intelligence
date: 2026/10/10
references:
    - https://zimperium.com/blog/mantax-otax-indonesian-mobile-ransomware-with-spyware-integration
logsource:
    product: android
    service: package_install
detection:
    selection_permissions:
        RequestedPermissions|contains|all:
            - 'android.permission.BIND_DEVICE_ADMIN'
            - 'android.permission.READ_SMS'
            - 'android.permission.READ_CONTACTS'
            - 'android.permission.BIND_ACCESSIBILITY_SERVICE'
    selection_source:
        InstallerPackage|not_contains:
            - 'com.android.vending'
            - 'com.google.android.gms'
    condition: selection_permissions and selection_source
falsepositives:
    - Legitimate MDM or enterprise security agents sideloaded during enrollment
level: high
tags:
    - attack.impact
    - attack.t1486
    - attack.collection
KQL — Microsoft Sentinel / Defender
// NEBULA / KNTRAT hunt: npm installs of malicious NebulaAI packages and C2 egress
let BadPkgs = dynamic(["api-nebula","llm-nebula"]);
let BadInfra = dynamic(["api.nebulaai.dev","65.87.7.132","fact-register.md"]);
union isfuzzy=true
(
    DeviceNetworkEvents
    | where TimeGenerated > ago(30d)
    | where RemoteUrl has_any (BadInfra) or RemoteIP == "65.87.7.132"
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort
),
(
    DeviceProcessEvents
    | where TimeGenerated > ago(30d)
    | where ProcessCommandLine has_any (BadPkgs)
       or (InitiatingProcessFileName in~ ("npm.exe","node.exe","npm.cmd")
           and FileName in~ ("powershell.exe","wscript.exe","cscript.exe","mshta.exe","rundll32.exe"))
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
),
(
    DeviceFileEvents
    | where TimeGenerated > ago(30d)
    | where FolderPath has "node_modules" and FolderPath has_any (BadPkgs)
       or FileName =~ "fact-register.md"
    | project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName
)
| sort by TimeGenerated desc
PowerShell
# NEBULA / KNTRAT IOC Hunt Script — Security Arsenal
# Run elevated on developer workstations, build agents, and CI runners.
$ErrorActionPreference = 'SilentlyContinue'
$findings = @()

Write-Host "[1/5] Checking npm global/local packages for malicious NebulaAI SDK..." -ForegroundColor Cyan
$badPkgs = @('api-nebula','llm-nebula')
foreach ($pkg in $badPkgs) {
    $installed = npm ls -g $pkg 2>$null
    if ($installed -match $pkg) {
        $findings += [PSCustomObject]@{Type='npm-global'; Indicator=$pkg; Detail=$installed}
    }
}
# Scan node_modules trees in common dev roots
$roots = @("$env:USERPROFILE\source","$env:USERPROFILE\repos","$env:USERPROFILE\projects","C:\agent\_work","C:\build")
foreach ($root in $roots) {
    if (Test-Path $root) {
        Get-ChildItem -Path $root -Recurse -Depth 6 -Directory -Filter 'node_modules' |
            ForEach-Object {
                Get-ChildItem $_.FullName -Directory | Where-Object { $_.Name -match 'nebula' } |
                    ForEach-Object { $findings += [PSCustomObject]@{Type='node_modules'; Indicator=$_.Name; Detail=$_.FullName} }
            }
    }
}

Write-Host "[2/5] Checking known KNTRAT file hashes..." -ForegroundColor Cyan
$badHashes = @(
    '5222dd57b8859e791a16abcf7f616bbc59f8cf248798c7c8c2ba800f0b52cd8c',
    '8bc90df9b387849338d9c61a8d379cfbb0d70ea576c0e37e1fb07ba164921807',
    'e99bab7b8bbbde7c821dae4ccfedfd1e608d65c466de9b08037c5ce5f56af3b1',
    'f0d36ac2d75c81a4c3cbdbf2f717db858f2876e6a1cc74f2d36b729a1dd51a5e'
)
foreach ($root in $roots) {
    if (Test-Path $root) {
        Get-ChildItem -Path $root -Recurse -File -Include *.exe,*.js,*.dll |
            ForEach-Object {
                $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
                if ($badHashes -contains $h) {
                    $findings += [PSCustomObject]@{Type='hash-match'; Indicator=$h; Detail=$_.FullName}
                }
            }
    }
}

Write-Host "[3/5] Checking active network connections to KNTRAT C2..." -ForegroundColor Cyan
Get-NetTCPConnection -State Established | Where-Object {
    $_.RemoteAddress -eq '65.87.7.132'
} | ForEach-Object {
    $proc = Get-Process -Id $_.OwningProcess
    $findings += [PSCustomObject]@{Type='c2-connection'; Indicator=$_.RemoteAddress; Detail="PID $($_.OwningProcess) - $($proc.ProcessName)"}
}

Write-Host "[4/5] Checking DNS cache for nebulaai.dev resolution..." -ForegroundColor Cyan
Get-DnsClientCache | Where-Object { $_.Entry -match 'nebulaai\.dev' } |
    ForEach-Object { $findings += [PSCustomObject]@{Type='dns-cache'; Indicator=$_.Entry; Detail=$_.Data} }

Write-Host "[5/5] Checking persistence locations for suspicious node/npm-launched entries..." -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
    Get-ItemProperty $key | Get-Member -MemberType NoteProperty | ForEach-Object {
        $val = (Get-ItemProperty $key -Name $_.Name).$($_.Name)
        if ($val -match 'node|npm|nebula') {
            $findings += [PSCustomObject]@{Type='persistence'; Indicator=$_.Name; Detail="$key = $val"}
        }
    }
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'node|npm' } |
    ForEach-Object { $findings += [PSCustomObject]@{Type='scheduled-task'; Indicator=$_.TaskName; Detail=$_.Actions.Execute} }

Write-Host "`n===== HUNT RESULTS =====" -ForegroundColor Yellow
if ($findings.Count -gt 0) {
    $findings | Format-Table -AutoSize
    $findings | Export-Csv -Path ".\nebular_kntrat_hunt_$(Get-Date -Format 'yyyyMMdd_HHmm').csv" -NoTypeInformation
    Write-Host "[!] $($findings.Count) findings exported to CSV. Escalate to IR immediately." -ForegroundColor Red
} else {
    Write-Host "[+] No KNTRAT/NEBULA indicators found on this host." -ForegroundColor Green
}

Response Priorities

Immediate (0–4 hours):

  • Block api.nebulaai.dev, 65.87.7.132, and https://api.nebulaai.dev/v2 at DNS, proxy, and firewall layers.
  • Bulk-ingest all 402 Mantax Otax hashes and 4 KNTRAT SHA256 hashes into EDR blocklists.
  • Audit all npm registries, lockfiles, and CI caches for api-nebula, llm-nebula, and any package published by nebulallms–nebulallms4. Pin and remove if present.
  • Search proxy/DNS logs for the last 30 days for connections to KNTRAT infrastructure — any hit is a confirmed compromise, not a lead.
  • Via MDM, inventory Android devices with sideloaded apps holding the admin+SMS+accessibility permission trio; isolate Indonesian-user BYOD devices showing the combination.

24 hours:

  • KNTRAT's HVNC capability means interactive sessions may have harvested credentials: force password resets and revoke sessions/tokens for any developer or service account on a host that installed the malicious packages. Rotate npm tokens, cloud keys, and SSH keys accessible from those machines.
  • For Mantax Otax infections, assume SMS 2FA codes and contacts were exfiltrated — reset credentials protected by SMS-based MFA and notify affected users of possible follow-on social engineering against their contact lists.
  • Verify no internal projects depend transitively on the malicious packages; rebuild artifacts produced during the exposure window.

1 week:

  • Enforce private npm registry proxying (Verdaccio/Nexus/Artifactory) with package-age quarantine — block packages younger than 14 days and block newly created publisher accounts by default.
  • Deploy the Sigma rules above fleet-wide and onboard Android MDM telemetry into the SIEM for the permission-abuse detection.
  • Restrict Firebase egress to an application allowlist on managed mobile devices; alert on Firebase traffic from non-approved apps.
  • Update developer security awareness: burner-account SDK packages impersonating AI tooling are an active lure theme.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.