ESET spots Mobile Trojan Android/Simplocker
2014-06-13
ESET saw the discovery of an interesting mobile trojan - the first spotting of a file-encrypting ransomware for Android. An Android Trojan, Android/Simplocker, was found on June 1, 2014 by ESET detection engineers.
Android/Simplocker setting foot on an Android device, scans the SD card for certain file types, encrypts them, and demands a ransom in order to decrypt the files. After launch, the Trojan will display the following ransom message and encrypt files in a separate thread in the background.
The ransom message is written in Russian and the payment demanded in Ukrainian hryvnias, so it is fair to assume that the threat is targeted against this region. This is not surprising, the very first Android SMS Trojans (including Android/Fakeplayer) back in 2010 also originated from Russia and Ukraine.
The sample researchers have analyzed is in the form of an application called “Sex xionix”. It was not found on the official Google Play and they estimate that its prevalence is very low at this time. Our analysis of the Android/Simplock.A sample revealed that they are most likely dealing with a proof-of-concept or a work in progress.
The malware is fully capable of encrypting the user's files, which may be lost if the encryption key is not retrieved. While the malware does contain functionality to decrypt the files, researchers strongly recommend against paying up – not only because that will only motivate other malware authors to continue these kinds of filthy operations, but also because there is no guarantee that the crook will keep their part of the deal and actually decrypt them.
Instead, they encourage users to protect themselves against these threats using prevention and defensive measures. For example, a mobile security app such as ESET Mobile Security for Android will keep malware off your device. Adhering to security best practices, such as keeping away from untrustworthy apps and app sources, will reduce your risks. And if you keep current backups of all your devices, then any ransomware or Filecoder trojan - be it on Android, Windows, or any operating system - is nothing more than a nuisance.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.