Tag Archive for: Ransomware

Android ransomware changes a device’s PIN code – Computerworld


Computerworld

Android ransomware changes a device's PIN code
Computerworld
Researchers at security company ESET have found a type of malware that changes an Android device's PIN, the first of its kind in an ever-evolving landscape of ransomware attacks. For most users, the only option to get rid of the malware is to reset the
New Android ransomware locks out victims by changing lock screen PINArs Technica
Aggressive Android ransomware spreading in the USAWe Live Security (blog)

all 47 news articles »

\\”android+ransomware\\” – read more

New Android ransomware locks out victims by changing lock screen PIN

Malicious apps that disable Android phones until owners pay a hefty ransom are growing increasingly malevolent and sophisticated as evidenced by a newly discovered sample that resets device PIN locks, an advance that requires a factory reset.

Dubbed Android/Lockerpin.A, the app first tricks inexperienced users into granting it device administrator privileges. To achieve this, it overlays a bogus patch installation window on top of an activation notice. When targets click on the continue button, they really grant the malicious app elevated rights that allow it to make changes to the Android settings. From there, Lockerpin sets or resets the PIN that unlocks the screen lock, effectively requiring users to perform a factory reset to regain control over the device. By contrast, earlier forms of Android ransomware generally were thwarted, usually by deactivating administrator privileges and then uninstalling the app after the infected device is booted into safe mode.

“After clicking on the button, the user’s device is doomed,” Lukas Stefanko, a researcher with antivirus provider Eset, wrote in a blog post published Thursday. “The trojan app has obtained administrator rights silently and now can lock [the] device—and even worse, it set[s] a new PIN for the lock screen. Not long after, the user will be prompted to pay a $ US500 ransom for allegedly viewing and harboring forbidden pornographic material.”

Read 2 remaining paragraphs | Comments

Ars Technica » Technology Lab

New Simplocker ransomware uses XMPP to bypass Android security apps – SC Magazine UK


SC Magazine UK

New Simplocker ransomware uses XMPP to bypass Android security apps
SC Magazine UK
Check Point has discovered a variant of the Simplocker ransomware program that uses a novel communications technique to bypass security. Researchers also garnered enough communications data to determine the success rate of the ransomware …

“android security” – read more

Black Hat 2015: Ransomware not all it’s cracked up to be

All ransomware is not created equal and therefore should not be universally feared, a researcher will tell the Black Hat 2015 conference this week.

Engin Kirda

Engin Kirda

In fact, some ransomware – which locks up infected computers until a demanded sum is paid – makes false claims about the damage it is capable of doing, and some of the data it purports to seize can be recovered, says Engin Kirda, the cofounder and chief architect at Lastline Labs.

To read this article in full or to leave a comment, please click here

Network World Tim Greene