logo

New DroidLock malware locks Android devices and demands a ransom

ID: 1ab903eb-0b71-5eb6-9759-8c19b2954cde

STIX ID: report--1ab903eb-0b71-5eb6-9759-8c19b2954cde

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A Zimperium report details DroidLock, an Android malware family distributed via malicious websites posing as legitimate apps that uses a dropper to install a secondary payload. DroidLock requests Device Admin and Accessibility permissions to lock devices with a ransom overlay, steal lock patterns and sensitive data, enable remote VNC control, and perform destructive actions (wipe, change PIN); victims are targeted via side-loaded APKs and Spanish-language lures, and users are advised to avoid sideloading and use Play Protect.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.