logo

Total Takeover: DroidLock Hijacks Your Device

ID: 784618a0-31e5-59a0-bf0c-c73d753ab08f

STIX ID: report--784618a0-31e5-59a0-bf0c-c73d753ab08f

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2025-12-10

Date Updated: 2026-05-01

...
...

zLabs researchers describe a malicious Android campaign named "DroidLock" that distributes a dropper via phishing to install a second-stage payload which abuses Accessibility and Device Admin privileges to display ransomware-style overlays, steal app credentials and lock patterns, intercept SMS/OTPs, record and exfiltrate screen and camera data, and enable remote control via VNC; the report includes technical analysis, a C2 command list, MITRE ATT&CK mappings, and links to IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.