Analyzing Android ‘Simplocker’ Ransomware.
ID: 02982576-cb2a-5dae-b75d-6d1acf66de03
STIX ID: report--02982576-cb2a-5dae-b75d-6d1acf66de03
Feed Name: Zscaler Security Research Blog
Threat Score
**Executive summary:** The report analyzes an Android ransomware family named 'Simplocker' that scans SD cards for media and document files, encrypts them with AES using a static key (appending ".enc"), displays a Russian ransom message demanding payment, harvests device identifiers (IMEI, model), and communicates with a Tor-based C2 (http://xeyocsu7fu2vjhxs.onion); the analysis includes sample metadata and IOCs (APK filename and MD5).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
