New DroidLock Malware Locks Android Devices and Demands a Ransom
The emergence of the DroidLock malware has introduced a significant threat to Android users, particularly in Spanish-speaking regions, through phishing websites. This malware combines ransomware methods with remote-control functionality, posing a severe…
The emergence of the DroidLock malware has introduced a significant threat to Android users, particularly in Spanish-speaking regions, through phishing websites. This malware combines ransomware methods with remote-control functionality, posing a severe risk to both personal and corporate devices.
DroidLock initiates its attack via a two-stage infection process. Initially, a dropper application deceives users by masquerading as a legitimate app, often imitating trusted services. This method enables the malware to bypass Android security and access critical accessibility services. Once installed, it requests device administrator and accessibility permissions, which users often grant without understanding the implications.
The malware's sophisticated architecture was identified by Zimperium security researchers. DroidLock uses both HTTP and WebSocket protocols to communicate with its command-and-control server, allowing attackers to send instructions and receive stolen data continuously. This bidirectional communication enables real-time control over compromised devices.
DroidLock employs two distinct overlay techniques to steal user credentials and unlock patterns. The first method utilizes a pattern-drawing interface embedded directly in the malware's code, capturing unlock patterns when users attempt to access their devices or banking applications. The second approach involves HTML-based overlays that mimic legitimate banking apps and login screens, tricking users into entering credentials into fake forms.
This malware combines ransomware methods with remote-control functionality, posing a severe risk to both personal and corporate devices.
The malware monitors applications opened by users and matches them against a server-provided list. If a match occurs, DroidLock deploys the corresponding overlay, targeting high-value applications like banking and payment systems.
Beyond credential theft, DroidLock records screen activity and captures images using the device camera, potentially exposing sensitive information such as one-time passwords and authentication codes. The ransomware component threatens to destroy all data within 24 hours, demanding payment via provided contact details. Unlike traditional ransomware, DroidLock can erase all data using factory reset commands, making prevention and detection crucial.
Effective security measures and user awareness are essential to prevent and detect such malware, as recovery post-infection is challenging without expert assistance.
Based on reporting by Cyber Security News.
