logo

New Android Ransomware

ID: a3b8aec8-d8b0-5cbc-863c-81bc0eb4be34

STIX ID: report--a3b8aec8-d8b0-5cbc-863c-81bc0eb4be34

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed a stealthy Android ransomware variant that automates repackaging of legitimate apps (including a popular Russian app) to inject an obfuscated payload which remains dormant for four hours, then prompts for device-admin rights, locks the screen with a ransom message, notifies a C2, and resists AV detection via encryption, reflection, and delayed execution; researchers found no data exfiltration or unlock capability, published SHA1 indicators, and recommended removal and defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.