
Cybercriminals extort money from Android Smart TV owners by encrypting their TVs with ransomware
It seems that no matter what security companies do to catch up, they can't keep up with cybercriminals who manage to take the next step, as a new type of ransomware has emerged.
While we used to think that cybercriminals were only interested in hacking websites, stealing passwords, etc., it seems that they have moved on to a new area of interest, which is the Internet of Things (IoT). In other words, if you have a Smart watch, Smart TV, Smart refrigerator, or any Internet-connected smart device, you need to be careful.
Trend Micro researchers have discovered a lockscreen ransomware for Android, known as “FLocker,” that can lock Android smartphones, as well as Smart TVs!
Echo Duan, a researcher at Trend Micro, wrote in a blog post that since FLocker was released in May 2015, the company has detected over 7,000 variants. The FLocker ransomware originally targeted Android smartphones, but its creators have added support for new changes to the Android system.
FLocker operates as a police Trojan and tries to scare the potential victim into paying by claiming to be the US Cybercrime Bureau or another law enforcement agency. Once the malware is downloaded and the TV is locked, the hacker accuses the victim of some offense and demands $200 in iTunes to unlock the device.
Ironically, the easier it is for owners to acquire multiple devices running on a single platform, the easier it becomes for hackers. “If malware infects one of those devices, that malware can eventually infect the others,” Duan wrote. “The malware is delivered via standard infection vectors: nothing new or special. The TVs in this case are an accidental collateral damage of the ransomware, not specifically targeted.”
There is a slight difference between the FLocker that attacks mobile devices and the version that attacks Smart TVs. “To avoid static analysis, FLocker hides code in files inside the ‘active’ folder. This file is called ‘Form.html’ and looks like a regular file. This gives the malware a chance to evade static code analysis.
Trend Micro says the malware has been configured to disable itself in certain regions, including Russia, Bulgaria, Hungary, Ukraine, Georgia, Kazakhstan, Azerbaijan, Armenia, and Belarus.
However, if FLocker detects devices outside of these countries, the malware will wait for 30 minutes. After the short waiting period, it immediately requests device administrator privileges. If the user denies the request, it will freeze the screen by inventing a system update. The ransomware website fits on the screen, regardless of whether it has infected a mobile phone or a smart TV.
Even though the new FLocker variant does not encrypt files, it has the ability to steal data from the device, including contacts, phone number, device information, and location. For those outside of Eastern Europe, Duan recommends in his blog, “we recommend that the user contact the device vendor as a first resort if their TV is infected.”
For victims who are more tech-savvy, they can potentially handle it themselves. “Another way to remove the malware is for the user to enable ADB debugging. Users can connect their device to a PC and launch ADB and run the command “PM clear %pkg%”. This kills the ransomware process and unlocks the screen. Users can then disable the admin privilege granted to the app on the device and uninstall the app.
He also emphasized, "To secure mobile devices, we advise you to install security software to protect them from malicious apps and threats." The next time your Android Smart TV refuses to play, you should suspect that it has been infected with malware.
