Security researchers analyzed the Koler Ransomware malware, which targets Android, and discovered that it has a sophisticated distribution infrastructure based on the TDS (Traffic Distribution System) system.
This ransomware, which has been identified as Android.OS.Koler.a, locks users' devices and demands a large sum of money in order to avoid criminal prosecution for viewing pornographic content.
Koler appears to operate under the same group behind the Reveton malware – which is based on the Citadel Trojan.
According to Kaspersky researchers, the malware targets desktop and mobile device users through a well-designed distribution network, which allows malicious actors to automatically launch new campaigns.
The attacks are based on a chain of redirects that ultimately lead the user to a site that serves the malicious malware installer (APK). The main redirect domain is videosartex.us.
Depending on the device they have, users may end up with a malicious Android app, browser-based ransomware, or a website with the Angler exploit Kit.
Victims are directed to the malicious sites via 49 adult content websites, which are used to distribute the malware.
