New DroidLock Malware Locks Android Devices and Demands Ransom Payment
## Cybersecurity: DroidLock Malware Threat
Cybersecurity: DroidLock Malware Threat
The zLabs research team has identified a new threat campaign targeting Spanish Android users through a malware strain known as DroidLock.
DroidLock differs from traditional ransomware by locking devices with overlays and demanding payment while maintaining control over the affected device. The malware is distributed via phishing websites that host deceptive applications. Once installed, it uses a two-stage infection process, starting with a dropper that prompts users to install a secondary payload containing the malicious code.
By exploiting accessibility services and device administrator privileges, DroidLock gains near-complete control over the device, employing 15 distinct commands to communicate with its command-and-control (C2) infrastructure.
The infection process begins with social engineering rather than technical exploitation. The dropper appears as a legitimate application, often imitating popular services such as Orange, to persuade users to grant installation permissions. Once executed, it requests accessibility services, which users often allow without understanding the implications.
With granted access, the malware automatically approves additional permissions for SMS access, call logs, contacts, and audio recording. The malware uses both websocket and HTTP communication to interact with its C2 server.
The zLabs research team has identified a new threat campaign targeting Spanish Android users through a malware strain known as DroidLock.
Upon receiving the appropriate command from its C2 server, DroidLock displays a full-screen WebView overlay with a threatening ransomware message. The overlay demands immediate contact with threat actors via email, requiring the victim's device ID for identification. The malware threatens complete data destruction within 24 hours if payment is not received.
Although this malware variant does not encrypt files like traditional ransomware, it has the capability to completely wipe the device. DroidLock can lock devices using device administrator privileges, change PINs and biometric authentication settings, perform factory resets, and access device screens remotely through VNC connections. The malware also captures images using the front-facing camera, silences audio, and maintains persistent screen recording capabilities.
DroidLock implements credential-stealing mechanisms through two overlay techniques. The first presents fake lock-pattern screens, while the second uses WebView overlays loaded with attacker-controlled HTML content that mimics legitimate banking and authentication applications.
The malware maintains a database of targeted applications, dynamically retrieving and displaying appropriate overlays when victims open specific apps.
Security researchers indicate that while DroidLock presents comprehensive device-takeover capabilities, their Mobile Threat Defense platform detects all identified samples through on-device dynamic detection engines. For enterprises, the implications are severe, as infected devices can intercept one-time passwords, change security credentials, and transform corporate handsets into hostile endpoints within managed networks.
The MITRE ATT&CK framework maps DroidLock across multiple tactics, from initial phishing-based access through credential access, collection, command-and-control, and eventual impact phases, demonstrating the sophistication of this emerging threat to mobile-dependent organizations.
Based on reporting by GBHackers.
