Table of Contents
Security researchers at ESET have discovered a new type of Android ransomware called DoubleLocker, which not only encrypts user data but also changes the device's PIN.
Doublelocker - New Ransomware Can Encrypt Data and Change Android Device PIN Overview
First discovered in May this year, this DoubleLocker ransomware has spread similarly to fake Adobe Flash updates through compromised sites.
DoubleLocker combines a smart infection mechanism with two powerful tools to blackmail its victims. Researchers believe that this ransomware could be upgraded in the future to steal bank certificates, not simply extort money from victims.
Lukáš Štefanko, an ESET malware researcher, said: "DoubleLocker can change the device's pin code, preventing the victim from accessing the phone and encrypting the victim's data. "Such a combination has never happened in the Android ecosystem. DoubleLocker also abuses Android access services - a popular trick in the cybercrime world."
- New ransomware appeared not to send Bitcoin, money, but. nude photos!!!
- Can data encryption protect you from Ransomware?
The Way Ransomware Doublelocker Works
Once installed and launched, the application will ask users to activate the malware access service called "Google Play Service". After the malware receives access rights, it will use them to activate device administrator rights and set itself as the default Home application without the user's consent. That is, whenever the user clicks the Home button, the ransomware will be activated and the device will be locked again. By using the access service, users do not know that they have started the malware by pressing the Home button.

DoubleLocker creates two reasons for the victim to pay a ransom. First, it changes the device's PIN, preventing the victim from using it. Second, it encrypts all data from the main storage directory on Android using AES encryption algorithm.
The ransom amount is set at a relatively modest level of 0. 0130 BTC (equivalent to 54 USD).
The best way to protect yourself is to always download applications from trusted sources like Google Play Store and verified developers. Besides, installing an antivirus application is also a safe way to protect your device from malware.
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does doublelocker - New Ransomware Can Encrypt Data and Change Android Device PIN matter?
Security researchers at ESET have discovered a new type of Android ransomware called DoubleLocker, which not only encrypts user data but also changes the device's PIN.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.