A more sophisticated version of the Svpeng Trojan for Android mobile devices has been recently detected and appears to be equipped with ransomware.
The threat appeared about a year ago, and at that time it was considered a typical SMS-Trojan targeting bank accounts, but it soon began to grow in sophistication as its creators targeted mobile banking users.
In early June, however, Kaspersky Lab researchers discovered a new version of Svpeng that includes ransomware.
Unlike the first malware (Android/ Simplocker – Trojan-Ransom.AndroidOS.Pletor.a) analyzed by ESET and Kaspersky, this one keeps the entire device blocked and not just specific files.
This is achieved by locking the smartphone until a ransom is paid. The device will not respond to any action except for the one that leads to the payment of the money or its shutdown. However, as soon as the device is back up and running, the Trojan immediately gains control again.
Similar to Trojan-Ransom.AndroidOS.Pletor.a, the new version of Svpeng takes a photo of the victim and displays it in the ransom message.
Once the device is infected and the malware is deployed, a fake scan is initiated, resulting in the detection of prohibited content and proceeds to lock the phone because it was “used to visit websites containing pornography,” which is “a violation of federal laws of the United States of America.”.
The ransom is $200 (€148) and victims are offered multiple payment methods, MoneyPak vouchers being one of them. In this case, there are several alternatives for purchasing them in the US.
expert Roman Unuchekwrites that unlike previous variants of the Trojan that targeted Russian citizens, this one focuses on residents of the United States. Other nations where the threat is present include the United Kingdom, Switzerland, Germany, India, and Russia.
