logo

DoubleLocker Android Ransomware

ID: 2c87780b-1e7e-5e20-af0a-b5fd2e2eeabf

STIX ID: report--2c87780b-1e7e-5e20-af0a-b5fd2e2eeabf

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

DoubleLocker is an Android ransomware distributed via fake Adobe Flash updates on compromised websites. It abuses accessibility services to install itself as the default home app, change the device PIN to a random value the attackers do not retain, and encrypt files using AES with a ".cryeye" extension; victims are asked to pay 0.0130 BTC (~$73) and must factory reset to regain access if they do not pay.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.