New DroidLock Malware Locks Android Devices and Demands a Ransom
ID: acccc958-a8d1-5576-b621-b1f690f199b2
STIX ID: report--acccc958-a8d1-5576-b621-b1f690f199b2
Feed Name: cybersecurityNews.com
**DroidLock** is a sophisticated Android malware campaign, spreading via phishing/dropper apps (notably in Spanish-speaking regions), that gains device-admin and accessibility privileges to perform real-time remote control, deploy overlays to steal banking credentials and unlock patterns, capture screen activity and camera images, and display ransom screens while retaining the ability to irreversibly erase devices via factory-reset commands; it communicates with attackers over HTTP and WebSocket for continuous control and targeted overlay delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
