Global XMPP Android Ransomware Campaign Hits 10,000 Devices
Check Point's malware research team has identified a new strain of mobile ransomware that encrypts the content of Android smartphones by introducing a new twist, both in how it communicates with its 'bosses' and how it motivates its victims to take action.
"We estimate that tens of thousands of devices have been infected. We have evidence that users have already paid hundreds of thousands of dollars to get their files back unencrypted, and the actual infection rate may be much higher," the research team said in a blog post.
The updated version of Simplocker masquerades in app stores and download pages as a legitimate application, and uses an open instant messaging protocol to connect to command and control servers.
Now, the owner of the phone sees a message informing him that his files are being held hostage. The message, which looks like an official document, is also not a new trick of the well-known NSA message: the "NSA" allegedly accuses the owner of the mobile phone of wrong 'exploits', such as browsing pornographic sites on his mobile, or violating copyrights by keeping/using protected content, such as videos, music, etc., and in order to regain access to his device, he will have to pay a "fine".
“The victim seems to have no alternative. The application cannot be removed by a typical user. Even if the user were somehow able to remove it, their files would still remain encrypted. The ransom payment, however, will probably never reach the NSA, but will rather find its way into the hands of a cybercriminal,” the group adds in its publication.
According to the group, while posing as a legal or government authority as a means of intimidating the victim into paying is not a new tactic, the use of Extensible Messaging and Presence Protocol (XMPP), the instant messaging protocol used by Jabber and previously by GTalk, is a change in their tactics in order to avoid detection by anti-malware tools.
Communicating via XMPP makes it more difficult for security tools and anti-malware to catch ransomware before it can communicate with its command and control network because it hides its communication in a format that resembles regular instant messaging communication.
Most of the previous ransomware packages have contacted a website over HTTPS to obtain the encryption keys; these websites can generally be identified by URLs, IP addresses, or the signature of the Web requests and then blocked.

