Android Ransomware Walkthrough and How to Unlock
ID: 012436ca-287d-5a69-b0bb-77d8de6d6ef6
STIX ID: report--012436ca-287d-5a69-b0bb-77d8de6d6ef6
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz analyzed an Android ransomware sample masquerading as a Coronavirus Tracker (package com.device.security, hash D1D417235616E4A05096319BB4875F57) that requests battery-optimization exemption, Accessibility access and device administrator rights to lock victims' phones and display a $250 bitcoin ransom. The report shows the ransomware does not use networking or file encryption, contains a hard-coded unlock PIN (4865083501), and provides steps to revoke privileges and uninstall the app; users are advised to install apps only from official stores and avoid unknown links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
