logo

New DroidLock Malware Locks Android Devices and Demands a Ransom

ID: acccc958-a8d1-5576-b621-b1f690f199b2

STIX ID: report--acccc958-a8d1-5576-b621-b1f690f199b2

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**DroidLock** is a sophisticated Android malware campaign, spreading via phishing/dropper apps (notably in Spanish-speaking regions), that gains device-admin and accessibility privileges to perform real-time remote control, deploy overlays to steal banking credentials and unlock patterns, capture screen activity and camera images, and display ransom screens while retaining the ability to irreversibly erase devices via factory-reset commands; it communicates with attackers over HTTP and WebSocket for continuous control and targeted overlay delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.