New Android Ransomware
ID: a3b8aec8-d8b0-5cbc-863c-81bc0eb4be34
STIX ID: report--a3b8aec8-d8b0-5cbc-863c-81bc0eb4be34
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ analyzed a stealthy Android ransomware variant that automates repackaging of legitimate apps (including a popular Russian app) to inject an obfuscated payload which remains dormant for four hours, then prompts for device-admin rights, locks the screen with a ransom message, notifies a C2, and resists AV detection via encryption, reflection, and delayed execution; researchers found no data exfiltration or unlock capability, published SHA1 indicators, and recommended removal and defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
