According to security researchers, the Android-based mobile ransomware Flocker has evolved significantly, now being able to infect and lock Android -based smart TVs .
The dangerous ransomware first appeared in May 2015 and since then its code has been constantly evolving, with Trend Micro having identified more than 7,000 different variants so far.
In April 2016 alone, at least 1,200 variants of FLocker were detected, while a visible increase in the severity of this threat was observed.
The powerful software bears several similarities to the Cyber.Police (Dogspectus) ransomware, which according to reports from security firms Blue Coat and Zimperium has the ability to infect Android devices without requiring user interaction.
[su_heading size=”18″ margin=”40″]The advanced version of Flocker is spread via Spam SMS with malicious links[/su_heading]
Once users download the malicious applications spread through these links, the malware remains hidden within an HTML file inside the “Assets” folder for 30 minutes, in order to avoid detection by any installed antivirus solutions.
After the 30-minute period has passed, Flocker begins to pressure users to grant it administrative privileges. If the user refuses, Flocker freezes the screen and displays a fake system update message asking users for the required access.
Once Flocker gains administrator privileges, it contacts the C&C server, from where it downloads another APK and an HTML & JS file.
FLοcker then displays a ransom note that covers the entire screen and launches the second APK, which encrypts the files with an encoded AES encryption key.
While in the past FLocker only targeted mobile devices, recent versions now also encrypt data from smart TVs running Android OS.


