ESET announced that its engineers have identified a new, dangerous ransomware for Android. Android/Simplocker, encrypts files on the SD card and then demands a ransom for their decryption.
The following is information from the company's Press Release.
While the encryption is taking place, a message in Russian appears on the device's screen , informing the Android user that their device has been compromised and 260 Ukrainian Hryvnias , approximately 16 euros , are required to regain control of it.
Android/Simplocker.A scans the device's SD card for jpeg, jpg, png, bmp, gif, pdf, doc, docx, txt, avi, mkv, 3gp, and mp4.
At the same time, it will send traceable information from the device (such as IMEI , etc.) to its own Command & Control server
The paradox, compared to previous examples of ransomware on Windows, is that there is no password entry field to confirm the payment; instead, the malware obeys a command from the C&C server to decrypt the files, likely after the payment has been made.
ESET experts have analyzed a sample of the attack in the form of an app called “Xionix Sex.” The app was not found on the official Google Play, which, according to their estimates, means that its spread is still very small.
As the malware does not have the functionality to decrypt files, ESET advises users not to proceed with paying the ransom, as there is no guarantee that the cybercriminals will keep their word and decrypt the data.
On the contrary, it encourages the use of powerful solutions, such as ESET Mobile Security, to protect the Android device and backup data, since this way the user does not risk losing any files from any similar trojan.
For more information and a more detailed analysis of the ransomware, interested parties can visit the blogpost www.welivesecurity.com/2014/06/04/simplocker/.
Source: e-pcmag.gr

