Skip to content
Telecom

Android ransomware abuses accessibility services

By Minjun Park
1 min read
www.androidpolice.comwp contentuploads201610nexus2cee galaxy s7edge coral blue 1 728x410 e6aacc307d45959333ff10319fac4c2e114618c8
www.androidpolice.comwp contentuploads201610nexus2cee galaxy s7edge coral blue 1 728×410 e6aacc307d45959333ff10319fac4c2e114618c8
In this article (4)

ESET researchers have discovered DoubleLocker, an innovative Android malware that combines a cunning infection mechanism with two powerful tools for extorting money from its victims.

“DoubleLocker misuses Android accessibility services, which is a popular trick among cybercriminals,” commented Lukáš Štefanko, the ESET malware researcher who discovered DoubleLocker.

“Its payload can change the device’s PIN, preventing the victim from accessing their device and encrypts the victim’s data. Such a combination hasn’t been seen yet in the Android ecosystem.”

On top of being ransomware, DoubleLocker is based on the foundations of a particular, already documented banking Trojan. According to Štefanko, the functionality for harvesting users’ banking credentials and wiping out their accounts can be added easily.

“The additional functionality will turn this malware into what can be called ransom-banker,” warns Lukáš Štefanko, who claims he spotted a test version of such a ransom-banker in the wild in May 2017.

Questions & Answers

Q.

What two primary methods does DoubleLocker use to extort money from its victims?

A.

DoubleLocker abuses Android accessibility services to change the device’s PIN, locking the user out. It also encrypts the victim's data, making it inaccessible without a key.

Q.

What additional functionality could be easily added to DoubleLocker, making it more dangerous?

A.

The malware could easily incorporate features from its banking Trojan foundations. This would allow it to harvest banking credentials and wipe out victims' accounts.

Q.

Who discovered DoubleLocker and when was a test version of the combined malware spotted?

A.

ESET malware researcher Lukáš Štefanko discovered DoubleLocker. He claims to have seen a test version of the 'ransom-banker' malware in the wild in May 2017.

Reader pulse

How concerned are you about this new Android threat?

19,798 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready