CovidLock: Mobile Coronavirus Tracking App Coughs Up Ransomware
ID: 8b3baa6c-d68a-56ed-9207-6d3dd587a07e
STIX ID: report--8b3baa6c-d68a-56ed-9207-6d3dd587a07e
Feed Name: DomainTools
DomainTools researchers identified a malicious Android application called "CovidLock" distributed from coronavirusapp.site that poses as a COVID-19 tracker; the app installs ransomware that changes the device unlock password (screen-lock attack), demands $100 in bitcoin, and threatens data deletion and public leaking of social accounts. DomainTools reversed the decryption keys, is monitoring the Bitcoin wallet, and recommends obtaining information from trusted sources, installing apps only from Google Play, and ensuring devices have a screen lock enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
