A New Android Ransomware Emerges
While the world waits for the next big ransomware campaign, Android users have one more concern in the form of DoubleLocker. According to the folks at ESET, this ransomware stands out from the rest by executing a double attack, which encrypts personal files with AES and changes the device PIN at the same time.
Cyberattacks are multiplying, and as users we must be very alert. Common sense is not infallible, as was proven after the CCleaner incident, however most campaigns out there bet on a lapse or the search for certain content (for example, the “free” streaming of a popular series). The risk is even greater if the user depends on a mobile device, since it does not receive security updates with the same frequency as the average computer. That makes Android a very tempting target, and the latest example to cause problems is DoubleLocker, a ransomware discovered by ESET.
How DoubleLocker Works
Available information indicates that DoubleLocker is based on the BankBot trojan. As its name suggests, DoubleLocker executes two attacks: The first encrypts the user’s personal files with AES, and the second modifies the device PIN. Once it achieves both objectives, DoubleLocker assumes the role of a screenlock and demands a special payment of 0.0130 bitcoins, something like 74 dollars at the time of writing. Its distribution follows a line similar to BankBot, downloading a fake copy of Adobe Flash Player through compromised sites. After opening it requests the activation of a service called “Google Play Service” (not “Services”). The list of permissions clearly reveals its malicious intentions, but if someone enables it without reading, well...
Recovery and Risks
Those infected with DoubleLocker have a 24-hour deadline, or all ways to decrypt the data will disappear. ESET researchers explain that because of its “banking” nature, DoubleLocker could be turned into something worse, say malware that attacks PayPal and bank accounts. The only way to recover the device is by doing a factory reset, unless it has root and its debugging mode is active. That would allow purging the fake PIN via ADB.
(Note from the editor: Several colleague sites report that DoubleLocker empties PayPal accounts, but this is not so. The ransomware does not have harvesting capability in its current version.)