Android ransomware abuses accessibility services

ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

“DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

“Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

“The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.

Latest articles

Food
Malaysia’s largest coffee chain Zus Coffee targets 200 Southeast Asian outlets this year

Sign up for newsletters


Must read

Behind the Buzz
Retail News Asia — Your Daily Fix of What’s Happening in Asian Retail

We’re here to keep you in the loop—every single day. Whether you’re running a small local shop, scaling an online biz, or part of a global brand making moves in Asia, we’ve got something for you.

With 50+ fresh stories a week and 13.6 million readers, Retail News Asia isn’t just another news site—it’s the go-to source for all things retail across the region.
Retail Updates
Fresh updates. Real insights. Delivered daily or weekly—no spam, just retail gold.

Copyright © 2014 -2025 | Retail News Asia