HomeSecurityElgato Ransomware Targets Androids | Steals SMS, Locks SD Card

Elgato Ransomware Targets Androids | Steals SMS, Locks SD Card

The Elgato ransomware family, which was recently discovered by Intel McAfee researchers, targets Android devices. Specifically, it locks the user's device, encrypts its files and even steals the user's SMS messages when requested.

The ransomware operates based on a control panel from which the scammers send commands to infected devices.

Intel McAfee researchers say that Elgato checks for new commands from the C&C server at regular intervals. These commands are sent to the ransomware over HTTP, without encryption.

Elgato Ransomware Targets Androids | Steals SMS, Locks SD Card

Some of the supported commands include the ability to forward and delete all SMS messages, send a message from the infected device, encrypt files on the SD card, or encrypt files from a specific path. All encrypted files will have the characteristic .enc file extension at the end.

Additionally, the crook can lock the user's screen and cause the ransomware to decrypt all previously encrypted files. In this way, the ransomware also serves as a decryptor after the user has paid the desired amount.

In its current version, Intel McAfee experts say that Elgato does not display a ransom note or demand money, but simply displays an image of an adorable cat every time it locks the user's screen. Hence the ransomware, El Gato, which means "The Cat" in Spanish.

Given that all communications occur via HTTP, researchers were able to locate the C&C server of Elgato, where -to their great surprise- they found the botnet control panel open to external connections, without requiring a password.

“This ransomware variant looks like a test version used for the commercialization of malware kits for cybercriminals, because the control server interface is not protected”, noted Fernando Ruiz, security expert at Intel McAfee. “McAfee Labs informed the owners of the affected servers and asked them to download the malicious service”, he added.

The overall low complexity of this vulnerability supports Ruiz's statements, which means this is an unfinished product, not yet ready for widespread distribution. The crooks will need to improve their encryption routines, deploy HTTPS for C&C server communication, and protect the botnet control panel with a login field.

elgato-control-panel

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS