DoubleLocker - new ransomware has the ability to encrypt data and change Android device PIN
Security researchers at ESET have discovered a new type of Android ransomware called DoubleLocker, which not only encrypts user data but also changes the device's PIN.
First discovered in May this year, this DoubleLocker ransomware has spread similarly to fake Adobe Flash updates through compromised sites.
DoubleLocker combines a smart infection mechanism with two powerful tools to blackmail its victims. Researchers believe that this ransomware could be upgraded in the future to steal bank certificates, not simply extort money from victims.
Lukáš Štefanko, an ESET malware researcher, said: "DoubleLocker has the ability to change the device's pin code, preventing the victim from accessing the phone and encrypting the victim's data. "Such a combination has never happened in the Android ecosystem. DoubleLocker also abuses Android access services - a popular trick in the cybercrime world."
- New ransomware appeared not to send Bitcoin, money, but . nude photos !!!
- Can data encryption protect you from Ransomware?
The way ransomware DoubleLocker works
Once installed and launched, the application will ask users to activate the malware access service called "Google Play Service". After the malware receives access rights, it will use them to activate device administrator rights and set itself as the default Home application without the user's consent. That is, whenever the user clicks the Home button, the ransomware will be activated and the device will be locked again. By using the access service, users do not know that they have started the malware by pressing the Home button.
DoubleLocker creates two reasons for the victim to pay a ransom. First, it changes the device's PIN, preventing the victim from using it. Second, it encrypts all data from the main storage directory on Android using AES encryption algorithm.
The ransom amount is set at a relatively modest level of 0.0130 BTC (equivalent to 54 USD).
The best way to protect yourself is to always download applications from trusted sources like Google Play Store and verified developers. Besides, installing an antivirus application is also a safe way to protect your device from malware.
You should read it
- 5 types of malware on Android
- List of the 3 most dangerous and scary Ransomware viruses
- Ransomware can encrypt cloud data
- General guidelines for decoding ransomware
- What is Ransomware Task Force (RTF)?
- How to decrypt encrypted files, recover data encrypted by Ransomware
- Warning ransomware fake game Cyberpunk 2077 for Android
- [Infographic] 7 effective ways to protect businesses from Ransomware
May be interested
- No anti-virus software can detect this extremely dangerous new Ransomware on Androida new type of ransomware on android has just been discovered by a researcher on a blog called zscaler. the point that makes this type of ransomware so frightening is that no anti-virus software can detect it.
- Warning campaign of large-scale ransomware attack, misuse of 7zip to encrypt QNAP devicesinternational cybersecurity researchers have warned of a massive ransomware attack against qnap devices around the world.
- How to change the name of an iOS or Android devicethere are many reasons why you want to change the name for your android or ios device, especially if you have many devices in your home. changing names makes it easy to distinguish them online. let's find out how to do it via the following article!
- This ransomware strain is specifically aimed at 'dirty' material of companiesransomware strains in general are tending to target data against victims in case they do not accept the required ransom.
- Another large Data Center service provider became a victim of ransomwareransomware appears to be redirecting attacks to major data centers on a global scale.
- How to encrypt Android messages with emojiemojicryption application will encrypt messages on android with emoji symbols, helping us limit the status of exposed messages and eavesdropping.
- Can data encryption protect you from Ransomware?many people believe that data encryption is a useful way to prevent ransomware from stealing user information. is that true? read the article below to know more!
- Why is Ransomware the perfect hack?it is difficult to get an accurate number of cyber attacks, but the available data on ransomware give a poor picture.
- Multipurpose data compressor for Androidzipme is a powerful tool to create zip packages for users to perform recovery settings for the star device when the rom is uploaded. anyone who uses android should be 'understanding the pain' when installing the rom for their android device, that is, restoring the applications and data currently in use on the device ..
- The official LooCipher ransomware decoder has been released, helping you to retrieve data completely freeloocipher is infected and installed on the victim's system through malicious word documents, can download the malicious executable file and run the file in the system.