logo

Android Ransomware 'Koler' Learns To Propagate Via SMS

ID: 4349e335-e086-52ba-8658-dd52c8922c53

STIX ID: report--4349e335-e086-52ba-8658-dd52c8922c53

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Android Koler is a mobile ransomware variant that arrives as a disguised APK (IMG_7821.apk) via a shortened Dropbox link, locks the device displaying a fake FBI warning demanding $300, and propagates by sending SMS messages with the download link to all contacts. The sample requests permissions including SEND_SMS and READ_CONTACTS, connects to a hardcoded C2 (http://admobtube.com/send.php?...), exfiltrates device info, uses an anti-VM Device ID check, and remains persistent after reboot; no file-encryption routine was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.