HT TECH wants to start sending you push notifications. Click allow to subscribe

This sophisticated ransomware kidnaps data on Android phones

Just like a kidnapper demands ransom to return the kidnapped individual, some ransomwares are bad actors that demand payment to not publish a victim’s data or block it and make it the data or the device inaccessible. Either way, it is digital extortion.

By: HT TECH
Updated on: Aug 20 2022, 23:31 IST
MalLocker.B is known to be hosted on random websites and is circulated via online forums and uses various social engineering lures. It often “masquerades” as popular apps, cracked games or video players, as per reports. (Pixabay)

According to a report published by Microsoft’s 365 Defender Research Team on October 8, ransomware has undergone a new evolution. The report stated that the research team had found a piece of particularly sophisticated Android ransomware with “novel techniques and behaviour” that exemplified the “rapid evolution of mobile threats” observed, writes PhoneArena.

This particular mobile ransomware, which was detected by Microsoft Defender for Endpoint “as AndroidOS/MalLocker.B” has been out in the wild for a while and has been constantly evolving.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
27% OFF
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹179,990₹245,900
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
2% OFF
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹78,990₹80,999
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,678₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

MalLocker.B is known to be hosted on random websites and is circulated via online forums and uses various social engineering lures. It often “masquerades” as popular apps, cracked games or video players, as per reports.

One of the versions particularly caught people’s attention since it was advanced malware with “unmistakable malicious characteristic and behaviour” but yet it managed to evade most of the available protections and had a low detection rate against many security solutions.

Ransom is demanded in the form of an instruction note that blocks access to your mobile phone’s display. The older versions of ransomware would rely on a permission called “SYSTEM_ALERT_WINDOW” that shows a pop-up window that cannot be dismissed or closed.

Also Read: Ransomware alert: Microsoft has a warning for all Android phone users

Designed originally for actual system alerts/errors, this permission feature was hijacked by bad actors and the UI was controlled by the hackers to cover the entire device screen instead of a small portion - rendering the whole screen unusable. This blocks the victims from being able to access their device and the only option they have is to pay up.

To fight this, Google retaliated by removing the SYSTEM_ALERT_WINDOW error and alert window. The permission status for SYSTEM_ALERT_WINDOW was also elevated to the special permissions category and out into the “above dangerous” category. This meant that instead of just a single click, users have to go through “many screens to approve apps that ask for permissions”.

Hackers then evolved the malware by using accessibility features, however, these were easily detectable. These malware-infected apps continued to evolve by using the “Call” notification and the “callback method” on Android - something that requires an users’ immediate attention.

The hackers started using a combination of both these features to trigger a ransom note on the device.

But this evolution story is not over yet.

According to the Microsoft 365 Defender Research Team report, recent variants of the ransomware contain “code forked from an open-source machine learning module used by developers to automatically resize and crop images based on screen size”. And this is a valuable function given the large variety of Android devices that exist.

The frozen TinyML model is useful for ensuring that images fit the device screen without any distortion. For this ransomware in particular, this model would make sure that the ransom note, which is usually a fake police notice or explicit images that have allegedly been found on the device, would appear to look more believable and thereby increase the chances of victims actually paying up.

Tanmay Ganacharya, Microsoft’s Defender research team lead, pointed out that this particular mobile ransomware variant hints at what one can expect from future malware attacks. 

The point is, MalLocker.B is constantly evolving and its main agenda is to make as much money from you as possible once it manages to hold your device or data 

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 20 Aug, 23:31 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
11% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹83,999₹93,999
Buy now
38% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
21% OFF
Asus VivoBook Pro 15 M6500RC HN741WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹58,990₹74,990
Buy now
15% OFF
Asus ROG Zephyrus G14 GA401QM K2268TS Laptop
  • Moonlight White with AniMe Matrix
  • 16 GB RAM
  • 1 TB SSD
₹178,300₹209,990
Buy now
22% OFF
Asus ROG Strix G15 G512LV AZ161T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS