Microsoft warns of a new form of mobile ransomware that uses incoming calls and Android's Home button to lock the device behind a ransom screen.
Discovery Ransomware Android
The newly discovered Ransomware is related to a variant of a well-known Android Ransomware family called “MalLocker.B” which has now resurfaced with a new technique. The purpose of the newfound Ransomware is to demand ransom payments on infected devices by rendering them unusable through an obfuscation mechanism. This development stems from a massive increase in ransomware attacks targeting critical infrastructure across various sectors. The daily average of ransomware attacks over the past three months has increased by 50% compared to the first half of the year. Cybercriminals are increasingly incorporating double extortion into their playbook.
MalLocker as Ransomware
MalLocker is known for being hosted on malicious websites and distributed on online forums using various kinds of social engineering by impersonating popular apps, cracked games or video players.
Previous Android ransomware cases abused Android accessibility features or a permission called "SYSTEM_ALERT_WINDOW" to display a persistent window on top of all other screens, presenting you with the ransom window. This window would typically pose as fake police messages or warn about the supposed discovery of explicit images on your private device. But just as anti-malware software began detecting this behavior, the new Android ransomware variant adapted its approach to overcome this barrier.
MalLocker new technique
MalLocker.B uses a new tactic where it permanently freezes your screen on an extortion screen and keeps it there until payment is made. To achieve this, the new ransomware variant exploits the "call" notification used to alert users to incoming calls, displaying a window that covers the entire screen. This call screen is then combined with a Home or Recents key to activate the ransom screen and bring it to the foreground.
In an effort to mask its true purpose, the Ransomware code is heavily hidden and rendered unreadable by name-mangle. In this way, there is deliberate use of meaningless variable names and unwanted code to thwart analysis. ”
This new mobile Ransomware variant is an important discovery, because this malware behavior has not been seen before and who knows, it could open even more doors for other malware.” According to Microsoft 365 Defender Research Team.
How do I protect my phone against Ransomware?
Flexamedia offers an internet security app to counter this kind of maliciousness. Do you want more information about this? Then take it without obligation touch with us.







