The number of users attacked by ransomware targeting Android devices has quadrupled in just one year, affecting at least 136,000 users worldwide. 
According to a Kaspersky Lab report on the ransomware threat landscape , the majority of attacks are based on just four groups of malware.
The report covers a two-year period, which, for comparison purposes, has been divided into two twelve-month periods: from April 2014 to March 2015 and from April 2015 to March 2016.
These specific time periods were chosen because they saw significant changes in the mobile ransomware threat landscape
Ransomware is a type of malware that blocks access to information on a victim's device, either by locking the screen with a special window or by encrypting important files, and then demanding a ransom. These programs are a highly recognized security problem.
But it's not just computer users who are at risk. The digital threat landscape for Android device owners is also filled with ransomware, as the report's key findings clearly show.
Important findings:
- The number of users attacked with mobile ransomware has increased almost fourfold: from 35,413 users in 2014-2015, to 136,532 users in 2015-2016.
- The percentage of users attacked by mobile ransomware compared to users attacked by any type of malware for Android devices also increased: from 2.04% in 2014-2015, to 4.63% in 2015-2016.
- Just four malware groups were responsible for over 90% of all attacks recorded during that period: the Small, Fusob, Pletor, and Svpeng malware families.
- Unlike the threats facing computers, where ransomware programs that use encryption processes (crypto-ransomware) have skyrocketed, while the number of attacks that lock screens (screen-blockers) has decreased, Android ransomware mostly takes the form of screen-blockers. This is due to the fact that Android devices cannot remove screen-blockers with the help of external hardware, which makes these programs as effective as crypto-ransomware for computers.
Although the actual number of mobile users attacked by ransomware is lower and the growth rate slower than that observed for desktop ransomware, the situation with Android ransomware is still worrying.
At the start of the comparison period, the monthly number of users encountering this type of malware on Android devices was almost zero, but by the end it had reached almost 30,000 users per month.
This clearly shows that criminals are actively exploring alternatives to computer attacks and that they will persist.
“The extortion model is here to stay. Mobileransomware emerged as a continuation of desktop ransomware, and it is likely that malware targeting devices that are very different from a computer or smartphone will follow. These could be connected devices, such as smart watches, smart TVs, and other smart products, including home and car entertainment systems. There are indications that this may happen for some of these devices, so the emergence of malware targeting smart devices is only a matter of time,” said Roman Unuchek, Mobile Security Expert at Kaspersky Lab.
To protect against mobile ransomware attacks, Kaspersky Lab recommends that users:
- Restrict the installation of applications from sources other than official app stores.
- Use a reliable security solution that can detect malware and malicious links.
- If installing apps from unofficial sources is unavoidable, then attention should be paid to what kind of permissions the app requests. Such apps should not be installed if the device does not have a security solution installed.
- Educate yourself and your loved ones about the latest forms of malware and how they spread. This helps to identify an attempted social engineering attack.
The full report is available on the Securelist.com.
