Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New DroidLock Malware Locks Android Devices and Demands Ransom Payment

## Cybersecurity: DroidLock Malware Threat

Cybersecurity: DroidLock Malware Threat

The zLabs research team has identified a new threat campaign targeting Spanish Android users through a malware strain known as DroidLock.

DroidLock differs from traditional ransomware by locking devices with overlays and demanding payment while maintaining control over the affected device. The malware is distributed via phishing websites that host deceptive applications. Once installed, it uses a two-stage infection process, starting with a dropper that prompts users to install a secondary payload containing the malicious code.

By exploiting accessibility services and device administrator privileges, DroidLock gains near-complete control over the device, employing 15 distinct commands to communicate with its command-and-control (C2) infrastructure.

The infection process begins with social engineering rather than technical exploitation. The dropper appears as a legitimate application, often imitating popular services such as Orange, to persuade users to grant installation permissions. Once executed, it requests accessibility services, which users often allow without understanding the implications.

With granted access, the malware automatically approves additional permissions for SMS access, call logs, contacts, and audio recording. The malware uses both websocket and HTTP communication to interact with its C2 server.

The zLabs research team has identified a new threat campaign targeting Spanish Android users through a malware strain known as DroidLock.
Jessica Grant · Thehackingpost

Upon receiving the appropriate command from its C2 server, DroidLock displays a full-screen WebView overlay with a threatening ransomware message. The overlay demands immediate contact with threat actors via email, requiring the victim's device ID for identification. The malware threatens complete data destruction within 24 hours if payment is not received.

Although this malware variant does not encrypt files like traditional ransomware, it has the capability to completely wipe the device. DroidLock can lock devices using device administrator privileges, change PINs and biometric authentication settings, perform factory resets, and access device screens remotely through VNC connections. The malware also captures images using the front-facing camera, silences audio, and maintains persistent screen recording capabilities.

DroidLock implements credential-stealing mechanisms through two overlay techniques. The first presents fake lock-pattern screens, while the second uses WebView overlays loaded with attacker-controlled HTML content that mimics legitimate banking and authentication applications.

The malware maintains a database of targeted applications, dynamically retrieving and displaying appropriate overlays when victims open specific apps.

Advertisement

Security researchers indicate that while DroidLock presents comprehensive device-takeover capabilities, their Mobile Threat Defense platform detects all identified samples through on-device dynamic detection engines. For enterprises, the implications are severe, as infected devices can intercept one-time passwords, change security credentials, and transform corporate handsets into hostile endpoints within managed networks.

The MITRE ATT&CK framework maps DroidLock across multiple tactics, from initial phishing-based access through credential access, collection, command-and-control, and eventual impact phases, demonstrating the sophistication of this emerging threat to mobile-dependent organizations.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories