
In recent months, hackers have been exploiting the COVID-19 situation to launch various scams. This time, a new ransomware that appears to be an Android app COVID-19 contact tracing is being used in attacks
Researchers from ESET said the new ransomware appeared just days after Health Canada announced the launch of its COVID Alert app , which will be tested first in Ontario before rolling out to all regions .
The official mobile app is expected to be released in at least a month. However, cybercriminals are trying to promote an Android packagethat claims to come from the government. The app the hackers appears to be the official COVID-19 contact tracing app, but it is malicious.
According to the researchers, two websites offered the fake app that appeared to be from Health Canada. However, the domains (now defunct), tracershield [.] Ca and covid19tracer [.] Ca, hosted APKs that, when downloaded, installed the CryCryptor ransomware on Android devices.

The ransomware caught ESET's attention after a user tweeted that the APKs were hiding a banking Trojan, but further investigation revealed that the malware is actually a new ransomware.
If an Android user downloads the APK from the fake domains and installs the app, the ransomware will request access to files and begin encrypting content on the device.
Finally, the .ENC extension is appended to the compromised files. Where the encrypted files are stored, there is also a ransom note.
ESET has managed to create a decryption tool for the current version of the Android ransomware, which is available on GitHub.
The ransomware was spotted on GitHub, with its source code made public on June 11. According to ESET, its developer, who named the open source malware CryDroid, said it was a research project.
“We reject the claim that the project was done for research purposes – no responsible researcher would publicly release a tool that is easy to use for malicious purposes,” ESET says.
GitHub has been informed of the true nature of the code.
