logo

Android Ransomware Walkthrough and How to Unlock

ID: 012436ca-287d-5a69-b0bb-77d8de6d6ef6

STIX ID: report--012436ca-287d-5a69-b0bb-77d8de6d6ef6

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz analyzed an Android ransomware sample masquerading as a Coronavirus Tracker (package com.device.security, hash D1D417235616E4A05096319BB4875F57) that requests battery-optimization exemption, Accessibility access and device administrator rights to lock victims' phones and display a $250 bitcoin ransom. The report shows the ransomware does not use networking or file encryption, contains a hard-coded unlock PIN (4865083501), and provides steps to revoke privileges and uninstall the app; users are advised to install apps only from official stores and avoid unknown links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.