Total Takeover: DroidLock Hijacks Your Device
ID: 784618a0-31e5-59a0-bf0c-c73d753ab08f
STIX ID: report--784618a0-31e5-59a0-bf0c-c73d753ab08f
Feed Name: Zimperium Blog
Threat Score
zLabs researchers describe a malicious Android campaign named "DroidLock" that distributes a dropper via phishing to install a second-stage payload which abuses Accessibility and Device Admin privileges to display ransomware-style overlays, steal app credentials and lock patterns, intercept SMS/OTPs, record and exfiltrate screen and camera data, and enable remote control via VNC; the report includes technical analysis, a C2 command list, MITRE ATT&CK mappings, and links to IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
