A ransomware app was recently discovered on Google Play that managed to hit at least one victim before the Android removed it.
According to security firm Check Point Software Technologies, a few weeks ago an Android device was detected to be infected with malware. It appears that the owner of the phone had downloaded an app that was infected with the so-called “charger” ransomware.
The app that carried the virus is called EnergyRescue and has now been removed from Google Play. Unfortunately, the virus managed to destroy the unfortunate owner's phone before the Android team could remove it. The infected app stole contacts, messages and requested administrator permission. Once the permission was confirmed, the ransomware locked the app and displayed the following message on the home screen:
"They must pay us, or parts of your personal information will be sold on the black market for 30 minutes. Pay the price and all files will be restored."
The hackers demanded 0.2 Bitcoins in exchange. Check Point notes that the payments were supposed to be made to a specific Bitcoin account, but no transactions have been detected so far.
Similar ransomware has been seen in the past, such as DataLust. That particular virus demanded around $15 to get people's data back. It seems that "Charger" is trying to create a mobile ransomware on par with the more prolific PC ransomware.
“Charger” follows the path of other Android malware before it by checking the exact location of infected phones. The phone does not seem to detect any malicious activity in Ukraine, Russia, and Belarus, so it is very likely that the hackers are coming from one of these places.
