{"id":593,"date":"2014-06-07T17:10:05","date_gmt":"2014-06-07T21:10:05","guid":{"rendered":"http:\/\/www.ccrepairservices.com\/blog\/?p=593"},"modified":"2014-06-07T17:20:13","modified_gmt":"2014-06-07T21:20:13","slug":"first-android-phone-ransomware-that-encrypts-your-sd-card-files","status":"publish","type":"post","link":"https:\/\/www.ccrepairservices.com\/blog\/virus-and-malware-threats\/first-android-phone-ransomware-that-encrypts-your-sd-card-files\/","title":{"rendered":"First Android Phone Ransomware that Encrypts your SD card Files"},"content":{"rendered":"<div style=\"text-align: justify;\">We have seen cybercriminals targeting PCs with Ransomware malware that encrypts your files or lock down your computer and ask for a ransom amount to be paid in a specified duration of time to unlock it.\n<div style=\"text-align: justify;\">To deliver the Ransomware malwares to the mobile devices, cyber criminals have already started creating malicious software programs for android devices. Last month, we reported about a new <i>Police Ransomware malware<\/i> that locks up the devices until the victims pay a ransom to get the keys to unlock the phone. But, the malware just lock the mobile screen and a loophole in the its implementation allowed users to recover their device and data stored on SDcard.\n<\/div>\n<p><\/p>\n<div style=\"text-align: justify;\">Now, in an effort to overcome this, threat actors have adopted encryption in the development of mobile Ransomware malwares. Recently, the security firm ESET has discovered a new Android ransomware, dubbed as <i>Android\/Simplocker.A<\/i>, that has ability to encrypt the files on the device SD card and then demand a ransom from the victim in order to decrypt those files.\n<\/div>\n<p><\/p>\n<div style=\"text-align: justify;\">Once installed, the malware scans the SD card for certain file types such as image, document or video with extensions &#8211; <i>jpeg, jpg, png, bmp, gif, pdf, doc, docx, txt, avi, mkv, 3gp, mp4<\/i> and encrypts them using AES in a separate thread in the background. After encrypting the files, the malware displays the following ransom message, written in Russian, which clearly means that this threat is targeting Russian Android users.\n<\/div>\n<blockquote class=\"tr_bq\" style=\"text-align: justify;\"><p>\u201c<i>WARNING your phone is locked!<br \/>\n<\/i><i>The device is locked for viewing and distributing child pornography , zoophilia and other perversions.<br \/>\n<\/i><i>To unlock you need to pay 260 UAH.<br \/>\n<\/i><i>1.) Locate the nearest payment kiosk.<\/i><br \/>\n<i>2.) Select MoneXy<\/i><br \/>\n<i>3.) Enter {REDACTED}.<\/i><br \/>\n<i>4.) Make deposit of 260 Hryvnia, and then press pay. Do not forget to take a receipt!<\/i><br \/>\n<i>After payment your device will be unlocked within 24 hours. In case of no PAYMENT YOU WILL LOSE ALL DATA ON your device!<\/i>\u201d<\/blockquote>\n<div style=\"text-align: justify;\">The Ransomware malware directs victim to pay the ransom amount i.e. 260 UAH, which is roughly equal to $21 US, through the MoneXy service, as this payment service is not easily traceable as the regular credit card.\n<p><img decoding=\"async\" title=\"mobile virus\" src=\"https:\/\/3.bp.blogspot.com\/-z82mTJvkePg\/U5Aqng-_X0I\/AAAAAAAAb80\/WZmTjMtWNPc\/s728\/mobile-virus.jpg\" alt=\"mobile virus\" border=\"0\" \/>\n<\/div>\n<div style=\"text-align: justify;\">\n<\/div>\n<p><\/p>\n<div style=\"text-align: justify;\">To maintain anonymity the malware author is using the Command-and-Control server hosted on TOR .onion domain and the malware sends the information of the infected device such as IMEI number to its server. <span style=\"color: #00ff00;\">The researchers at ESET are still analysing the malware:<\/span>\n<\/div>\n<blockquote class=\"tr_bq\" style=\"text-align: justify;\"><p>\u201c<i>Our analysis of the Android\/Simplock.A sample revealed that we are most likely dealing with a proof-of-concept or a work in progress \u2013 for example, the implementation of the encryption\u00a0doesn&#8217;t\u00a0come close to \u201cthe infamous Cryptolocker\u201d on Windows.<\/i>\u201d<\/blockquote>\n<div style=\"text-align: justify;\">The researchers have found that the malware is capable to encrypt the victim\u2019s files, which could be lost if the decryption key is not retrieved from the malware author by paying the ransom amount, but on the other hand the researchers strongly advise users against paying fine, as their is no guarantee that the hacker will provide you decryption keys even after paying the amount.\n<\/div>\n<div style=\"text-align: justify;\">\n<\/div>\n<div style=\"text-align: justify;\">Unfortunately, mobile antivirus products are only capable to detect such known\/detected threats only and can&#8217;t detect similar the new threats. So, it is important for you to always keep the back-up of all your files either manually on the computer system or use cloud backup services like dropbox, google drive etc, in order to protect it from the emerging threats.\n<\/div>\n<div style=\"text-align: justify;\">\n<\/div>\n<div style=\"text-align: justify;\">\n<h2 style=\"text-align: center;\"><span style=\"color: #00ff00;\">Please Visit our <a href=\"https:\/\/www.ccrepairservices.com\">Computer News Website and Blog<\/a><\/span><\/h2>\n<h1 style=\"text-align: center;\"><span style=\"color: #ff6600;\"> for latest computer repair and online news.<\/span><\/h1>\n<h2 style=\"text-align: center;\"><span style=\"color: #993300;\">Local and Online Virus removal and computer repairs anytime, anywhere<\/span><\/h2>\n<p style=\"text-align: center;\">Fort Lauderdale, Miami, Boca Raton, Boynton Beach and all South Florida<\/p>\n<\/div>\n<\/div>\n<div id=\"greasedLightboxOverlay\" style=\"display: none; height: 1315px;\">\n<div id=\"greasedLightbox\" style=\"display: none; top: 824.5px; left: 59px; visibility: visible;\"><img loading=\"lazy\" decoding=\"async\" id=\"greasedLightboxImage\" src=\"https:\/\/3.bp.blogspot.com\/-z82mTJvkePg\/U5Aqng-_X0I\/AAAAAAAAb80\/WZmTjMtWNPc\/s1600\/mobile-virus.jpg\" alt=\"\" width=\"705\" height=\"436\" \/><\/p>\n<div id=\"greasedLightboxCaption\" style=\"display: block;\">mobile virus\n<\/div>\n<\/div>\n<\/div>\n<div id=\"greasedLightboxMenu\" style=\"display: none;\"><a id=\"greasedLightboxTitleLink\" href=\"https:\/\/shiftingpixel.com\/lightbox\/\">Greased Lightbox<\/a><\/p>\n<div id=\"greasedLightboxButtons\"><a id=\"greasedLightboxButtonRight\" title=\"Next image (right arrow key)\"><\/a>\u2192<a id=\"greasedLightboxButtonLeft\" title=\"Previous image (left arrow key)\"><\/a>\u2190<a id=\"greasedLightboxButtonPlus\" title=\"Magnify image (+ key)\"><\/a>+<a id=\"greasedLightboxButtonMinus\" title=\"Shrink image (- key)\"><\/a>&#8211;<a id=\"greasedLightboxButtonSlide\" title=\"Start\/stop slideshow\"><\/a>\u21bb\n<\/div>\n<\/div>\n<div id=\"greasedLightboxLoading\" style=\"visibility: visible; display: none; top: 959.5px; left: 272px;\">\n<p id=\"greasedLightboxLoadingText\">Loading image<\/p>\n<p id=\"greasedLightboxLoadingHelp\">Click anywhere to cancel<\/p>\n<\/div>\n<div id=\"greasedLightboxError\" style=\"display: none;\">\n<p>Image unavailable<\/p>\n<p id=\"greasedLightboxErrorContext\">\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have seen cybercriminals targeting PCs with Ransomware malware that encrypts your files or lock down your computer and ask for a ransom amount to be paid in a specified duration of time to unlock it. To deliver the Ransomware malwares to the mobile devices, cyber criminals have already started creating malicious software programs for android devices. Last month, we reported about a new Police Ransomware malware that locks up the devices until the victims pay a ransom to get the keys to unlock the phone. But, the malware just lock the mobile screen and a loophole in the its implementation allowed users to recover their device and data stored on SDcard. Now, in an effort to overcome this, threat actors have adopted encryption in the development of mobile Ransomware malwares. Recently, the security firm ESET has discovered a new Android ransomware, dubbed as Android\/Simplocker.A, that has ability to encrypt the files on the device SD card and then demand a ransom from the victim in order to decrypt those files. Once installed, the malware scans the SD card for certain file types such as image, document or video with extensions &#8211; jpeg, jpg, png, bmp, gif, pdf, doc, docx, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[827,103,19,32,828,486,553,628,156,33,453,10,830,451,157,21,826,831,829,7,832,22],"class_list":["post-593","post","type-post","status-publish","format-standard","hentry","category-virus-and-malware-threats","tag-android-virus","tag-computer-news-2","tag-computer-repair","tag-fort-lauderdale","tag-iphone-virus","tag-latest-news","tag-latest-viruses","tag-local-news","tag-malware","tag-miami","tag-new-malware","tag-new-virus","tag-online-malware","tag-online-news","tag-online-threats","tag-online-virus","tag-phone-virus","tag-south-florida-local-news","tag-threats","tag-virus","tag-virus-attack","tag-virus-removal"],"_links":{"self":[{"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/posts\/593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/comments?post=593"}],"version-history":[{"count":6,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/posts\/593\/revisions"}],"predecessor-version":[{"id":600,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/posts\/593\/revisions\/600"}],"wp:attachment":[{"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/media?parent=593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/categories?post=593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ccrepairservices.com\/blog\/wp-json\/wp\/v2\/tags?post=593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}