Over 1,000 users had downloaded Lockdroid, but Google warned them in time to prevent them from installing a threat.
At the Security Analyst Summit (SAS 2016) held in Tenerife, Spain last week, Jelena Kovacina, a senior security analyst at Google, said that no Android users were tricked into installing the Lockdroid ransomware.
Cybersecurity firm Symantec detected a new variant of the Android.Lockdroid ransomware towards the end of January.
This particular version abused an older UI feature that allowed the malware author to show a secondary surface at the top of the screen and required administrator privileges for the application infected with the Lockdroid ransomware.
When users clicked the button that read “Continue” (on the top surface), they unknowingly clicked the “Activate” button that appeared below, as part of an attack scenario known as Clickjacking.
This issue affected two-thirds of the Android, which is over a billion users. More specifically, the issue affected those users who were using Android operating system versions prior to 5.0 (Lollipop).
Speaking at SAS 2016, Ms. Kovakina told the audience that Google's built-in Verify Apps security system had detected and warned all users who had downloaded the Lockdroid infected app from a third-party app store.
The analyst said that around 1,000 Android users had downloaded apps related to Lockdroid, but none of the users went through with the installation, mainly due to Android.
Google's Verify Apps was introduced in Android 4.2 and works by scanning all downloaded .apk packages for Potentially Harmful Applications, also known as PHAs (Potentially Harmful Applications).
“Google’s systems use machine learning to see patterns and make connections that humans wouldn’t,” Google researchers describe the system. This includes scanning for threats in apps downloaded from both the Play Storeand other sources.
Verify Apps will scan for known attack vectors and scenarios, such as phishing, rooting operations, ransomware, backdoors, spyware, malicious websites, SMS fraud, WAP fraud, phone fraud, and more.
This security feature is activated when you try to install apps from unverified sources and can be disabled. By default, Verify Apps comes enabled for all devices, and in this case, it seems like it could help suppress the spread of a dangerous ransomware campaign.


