Android ransomware abuses accessibility services

www.androidpolice.comwp-contentuploads201610nexus2cee_galaxy-s7edge-coral-blue-1-728x410-e6aacc307d45959333ff10319fac4c2e114618c8-1024x1024.jpg

ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

“DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

“Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

“The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.


About Retail News Asia

Retail News Asia is committed to providing local and global retailers with the latest news from the Asian retail market on a daily basis.

We have resources for everyone from independently owned business owners to online-only retailers and major chains expanding their reach throughout the Asian market. Retail News is “the news source” with over 50 weekly posts and 13,6 million readers.


CONTACT US

CALL US ANYTIME

Most read



Retail updates

Stay up to date of the lates updates and retail news from Asia.








X