A new and particularly dangerous Android malware, known as DroidLock, has raised alarm in the international cybersecurity community. The malware has the ability to completely lock victims' devices, demanding a ransom for their "release", while also gaining access to sensitive data such as messages, contacts, call logs and even audio recordings.
Full remote control via VNC
One of the most worrying aspects of DroidLock is that it allows its operator to gain complete control of the device via a built-in VNC-like mechanism. This way, the attacker can manipulate the device as if they were holding it in their own hands. The software can even steal the lock pattern by displaying a discreet overlay on the screen, recording the exact pattern.
See also: Spiderman: New phishing kit targets European banks
How it spreads: Fake apps and deceptive websites
Researchers at cybersecurity firm Zimperium report that DroidLock primarily targets Spanish-speaking users. It is distributed via deceptive websites that host fake applicationsthat mimic well-known and legitimate software packages. Once the user is tricked into installing the application, the malware is activated via a dropper that downloads the main malicious file.
According to the Zimperium report, the infection process relies on the use of an update: the fake app displays a supposedly “update,” which actually installs the malicious payload. It then requests critical permissions — such as Device Administrator and Accessibility Services — giving the attacker the ability to perform virtually any action on the phone.

What can DroidLock do?
Technical analysis revealed that the malware supports at least 15 different commands, allowing functions such as:
- sending notifications to the victim
- display overlays that steal data
- mute or restart the device
- camera startup
- factory reset
- uninstall applications
- change PIN, password or biometric data
With these capabilities, the attacker can remove all access from the legitimate owner of the device.
See also: Vishing attack abuses Teams & QuickAssist to deploy .NET malware
Ransomware via WebView and data destruction threats
DroidLock does not actually encrypt files — something we see in classic ransomware. However, it uses a “ransom screen” that loads via WebView upon receiving a command from its operator. The screen informs the victim that they must contact the threat actor via email and pay a ransom within 24 hours. Otherwise, the data will supposedly be permanently deleted.

Although no encryption is used, the simple threat of permanent destruction combined with absolute control of the device is enough to force many users to comply.
Hidden pattern lock collection
Another trick of DroidLock is that it displays a “dual” lock screen, recording the pattern drawn by the user. With this element, the attacker gains full access to the device even when the user tries to protect it. Goal: unhindered remote access via VNC, even when the phone is idle.
See also: STAC6565 targets Canada while Gold Blade develops QWCrypt Ransomware

Treatment and protection
As a member of the Google App Defense Alliance, Zimperium immediately shares its findings with Google’s security team, so Play Protect is already detecting the threat on updated devices.
To protect users, the following are recommended:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- avoid installing APKs from unknown sources
- check application permissions before and after installation
- regular device check with Play Protect
- download applications exclusively from trusted stores
Source: www.bleepingcomputer.com
