A new strain of mobile ransomware is abusing the mechanisms behind the “incoming call” notification and the “Home” button to lock your device screens. Dubbed AndroidOS/MalLocker.B, the ransomware hides in Android apps offered for download on online forums and third-party websites.
Like most Android ransomware strains, MalLocker.B does not actually encrypt the victim's files, but simply prevents access to the rest of the phone.

Once installed, the ransomware takes over the phone and prevents the user from closing/dismissing the ransom note – which is designed to look like a message from local law enforcement telling users that they committed a crime and must pay a fine.
Ransomware that pretends to be a fake police has been the most popular form of Android ransomware for more than half a decade.
Over time, these malware strains have abused various features of Android operating systems to keep users locked to their home screen.
Previous techniques included abusing the System Alert window or disabling functions that interface with the rest buttons .
MalLocker.B comes with a new variation of these techniques.
The ransomware uses two parts to display the ransom.
The first part abuses the “call” notification. This is the feature that is activated for incoming calls to display details about the caller, and MalLocker.B uses it to display a window that covers the entire screen area with details about the incoming call.
The second part abuses the “onUserLeaveHint()” function. This function is called when users want to send an app to the background and switch to a new app, and is triggered when buttons like Home or Recents are pressed. MalLocker.B abuses this function to bring the ransom note back to the foreground.
Abusing these two functions is a new trick that has never been seen before, but ransomware that hacks the Home has appeared before.
For example, in 2017, ESET discovered an Android ransomware strain called DoubleLocker that abused the accessibility service to reactivate itself after users pressed the Home button.
Users are advised to avoid installing Android apps downloaded from third-party sites, such as forums, website , or unauthorized third-party app.
