HomeSecurityDroidLock malware locks devices and demands ransom

DroidLock malware locks devices and demands ransom

A new and particularly dangerous Android malware, known as DroidLock, has raised alarm in the international cybersecurity community. The malware has the ability to completely lock victims' devices, demanding a ransom for their "release", while also gaining access to sensitive data such as messages, contacts, call logs and even audio recordings.

Full remote control via VNC

One of the most worrying aspects of DroidLock is that it allows its operator to gain complete control of the device via a built-in VNC-like mechanism. This way, the attacker can manipulate the device as if they were holding it in their own hands. The software can even steal the lock pattern by displaying a discreet overlay on the screen, recording the exact pattern.

See also: Spiderman: New phishing kit targets European banks

How it spreads: Fake apps and deceptive websites

Researchers at cybersecurity firm Zimperium report that DroidLock primarily targets Spanish-speaking users. It is distributed via deceptive websites that host fake applicationsthat mimic well-known and legitimate software packages. Once the user is tricked into installing the application, the malware is activated via a dropper that downloads the main malicious file.

According to the Zimperium report, the infection process relies on the use of an update: the fake app displays a supposedly “update,” which actually installs the malicious payload. It then requests critical permissions — such as Device Administrator and Accessibility Services — giving the attacker the ability to perform virtually any action on the phone.

DroidLock malware

What can DroidLock do?

Technical analysis revealed that the malware supports at least 15 different commands, allowing functions such as:

  • sending notifications to the victim
  • display overlays that steal data
  • mute or restart the device
  • camera startup
  • factory reset
  • uninstall applications
  • change PIN, password or biometric data

With these capabilities, the attacker can remove all access from the legitimate owner of the device.

See also: Vishing attack abuses Teams & QuickAssist to deploy .NET malware

Ransomware via WebView and data destruction threats

DroidLock does not actually encrypt files — something we see in classic ransomware. However, it uses a “ransom screen” that loads via WebView upon receiving a command from its operator. The screen informs the victim that they must contact the threat actor via email and pay a ransom within 24 hours. Otherwise, the data will supposedly be permanently deleted.

Android adware

Although no encryption is used, the simple threat of permanent destruction combined with absolute control of the device is enough to force many users to comply.

Hidden pattern lock collection

Another trick of DroidLock is that it displays a “dual” lock screen, recording the pattern drawn by the user. With this element, the attacker gains full access to the device even when the user tries to protect it. Goal: unhindered remote access via VNC, even when the phone is idle.

See also: STAC6565 targets Canada while Gold Blade develops QWCrypt Ransomware

DroidLock malware locks devices and demands ransom

Treatment and protection

As a member of the Google App Defense Alliance, Zimperium immediately shares its findings with Google’s security team, so Play Protect is already detecting the threat on updated devices.

To protect users, the following are recommended:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • avoid installing APKs from unknown sources
  • check application permissions before and after installation
  • regular device check with Play Protect
  • download applications exclusively from trusted stores

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS