Sinister Android Lock-Screen Ransomware Discovered

android-malware-623x360

There has been recent reports of the evolution and mass spreading of Android ransomware for a while now. With early ransomware families combining fake antivirus having the ability to lock device screen (Android Defender, for example), last year Simplocker was discovered the first Android ransomeware that actually encrypts user files. Now something more sinister is lurking, anti-virus research team at ESET have discovered the first known Android lock-screen-type ransomware spreading in the wild that sets the phone’s PIN lock.

In previous Android LockScreen Trojans, the screen-locking functionality was usually achieved by constantly bringing the ransom window to the foreground in an infinite loop. While various self-defense mechanisms were implemented to keep the device user locked out, it wasn’t too difficult to get rid of the malware thus unlocking the device by using Android Debug Bridge (ADB) or deactivating Administrator rights and uninstalling the malicious application in Safe Mode.

Unfortunately, malware writers have stepped up their game, and with the new Android ransom-lockers, as Android/Lockerpin.A, users have no effective way of regaining access to their device without root privileges or without some other form of security management solution installed, apart from a factory reset that would also delete all their data.

Moreover, this ransomware also uses a nasty trick to obtain and preserve Device Administrator privileges so as to prevent uninstallation. This is the first case in which we have observed this aggressive method in Android malware.

Analysis

After a successful installation, the malware tries to obtain Device Administrator privileges. This trick is being used by Android malware authors more and more, as it makes it more difficult to remove the infection. Earlier versions of this Android/Locker family do this in just the same way as all other Android Trojans – they rely on the user willingly activating the elevated privileges.

In the latest versions, however, the Trojan obtains Device Administrator rights much more covertly. The activation window is overlaid with the Trojan’s malicious window pretending to be an “Update patch installation”. As the victims click through this innocuous-looking installation they also unknowingly activate the Device Administrator privileges in the hidden underlying window.

1-576x1024

After clicking on the button, the user’s device is doomed: the Trojan app has obtained Administrator rights silently and now can lock device — and even worse, it set a new PIN for the lock screen.

Not long after, the user will be prompted to pay a $US500 ransom for allegedly viewing and harboring forbidden pornographic material.

Courtesy: ESET Research Team

Tags

Share this post:

Comment what you think!