logo

Android Ransomware - Porn Droid

ID: f39bcc78-8238-5a29-aeca-7b0b639a6161

STIX ID: report--f39bcc78-8238-5a29-aeca-7b0b639a6161

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a Porn Droid Android ransomware variant that lures users with a pornographic file, requests device administrator privileges under the guise of a Google patch, and locks the device with a fake FBI warning demanding USD 500. The malware harvests browser history and device details (IMEI, phone number), can take front-facing photos to intimidate victims, terminate certain AV apps, execute remote commands (destroy, unlock), and communicates with a hardcoded C2 (facebook-tw.zp.ua/pafumokat/bloqyxpn.php). Indicators include the dropped URL (http://sbqujqosyw.offer-mobi.com/mmesuofyqq1/pornvideo.apk) and MD5 857b887982f11493b4a1db953161e627; recommended mitigation is to install apps only from official stores and avoid sideloading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.