DroidLock malware locks you out of your Android device and demands ransom
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是一个针对安卓用户的新型威胁活动,恶意软件叫DroidLock。它通过钓鱼网站传播,伪装成可信品牌的应用。一旦安装,它会利用设备管理权限和无障碍服务权限完全控制设备。然后,它会索要更多权限,比如访问短信、通话记录、联系人和音频。此外,它还能创建覆盖层来捕捉解锁模式和应用凭证,并通过VNC远程控制设备。赎金威胁如果不支付就会删除文件或更改PIN码。 文章还提到研究人员警告说DroidLock可以删除设备内容、拦截一次性密码,并远程控制界面。虽然不像传统勒索软件那样加密文件,但通过阻止访问和威胁破坏数据来达到勒索目的。 防范建议包括只从官方商店安装应用、审查开发者信息、使用防恶意软件工具、谨慎授权权限以及保持系统更新。 现在我要把这些信息浓缩到100字以内。重点包括:恶意软件名称、传播方式、功能(控制设备、索要权限、远程访问)、赎金威胁以及防范建议。 可能的结构:描述恶意软件及其传播方式,说明其功能和威胁,最后提到防范措施。 确保语言简洁明了,避免重复。 </think> 研究人员发现了一种名为DroidLock的新恶意软件,通过伪装成可信品牌的钓鱼网站传播。该软件利用设备管理权限和无障碍服务权限完全控制安卓设备,并索要更多权限以进行远程操作和数据窃取。攻击者通过威胁删除文件或更改PIN码来勒索赎金。用户应谨慎安装应用并审查权限以防范此类威胁。 2025-12-11 16:57:58 Author: www.malwarebytes.com(查看原文) 阅读量:1 收藏

Researchers have analyzed a new threat campaign actively targeting Android users. The malware, named DroidLock, takes over a device and then holds it for ransom. The campaign to date has primarily targeted Spanish-speaking users, but researchers warn it could spread.

DroidLock is delivered via phishing sites that trick users into installing a malicious app pretending to be, for example, a telecom provider or other familiar brand. The app is really a dropper that installs malware able to take complete control of the device by abusing Device Admin and Accessibility Services permissions.

Once the victim grants accessibility permission, the malware starts approving additional permissions on its own. This can include access to SMS, call logs, contacts, and audio, which gives attackers more leverage in a ransom demand.

DroidLock also leverages Accessibility Services to create overlays on other apps. The overlays can capture device unlock patterns (giving the attacker full access) and also show a fake Android update screen, instructing victims not to power off or restart their devices.

DroidLock uses Virtual Network Computing (VNC) for remote access and control. With this, attackers can control the device in real time, including starting camera, muting sound, manipulating notifications, and uninstalling apps, and use overlays to capture lock patterns and app credentials. They can also deny access to the device by changing the PIN.

The researchers warn that:

“Once installed, DroidLock can wipe devices, change PINs, intercept OTPs (One-Time Passwords), and remotely control the user interface”

Unlike regular ransomware, DroidLock doesn’t encrypt files. But by blocking access and threatening to destroy everything unless a ransom is paid, it reaches the same outcome.

ransom note
Image courtesy of Zimperium

Urgent
Last chance
Time remaining {starts at 24 hours}
After this all files wil be deleted forever!
Your files will be permanently destroyed!
Contact us immediately at this email or lose everything forever: {email address}
Include your device ID {ID}
Payment required within 24 hours
No police, no recovery tools, no tricks
Every second counts!

How to stay safe

If this campaign turns out to be successful in Spain, we’ll undoubtedly see it emerge in other countries as well. So here are a few pointers to stay safe:

  • Only install apps from official app stores and avoid installing apps promoted in links in SMS, email, or messaging apps.
  • Before installing apps, verify the developer name, number of downloads, and user reviews rather than trusting a single promotional link.
  • Protect your devices. Use an up-to-date real-time anti-malware solution like Malwarebytes for Android, which already detects this malware.
  • Scrutinize permissions. Does an app really need the permissions it’s requesting to do the job you want it to do? Especially if it asks for accessibility, SMS, or camera access.
  • Keep Android, Google Play services, and all important apps up to date to get the latest security fixes.

We don’t just report on phone security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by downloading Malwarebytes for iOS, and Malwarebytes for Android today.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/news/2025/12/droidlock-malware-locks-you-out-of-your-android-device-and-demands-ransom
如有侵权请联系:admin#unsafe.sh