Security researchers have discovered a new ransomware called DoubleLocker which infects Android devices.The specialty of DoubleLocker ransomware is that it can change device’s PIN which prevents users from accessing their device and also encrypts the data
In capsule:
- New ransomware named DoubleLocker infects android devices
- Discovered by security researchers in ESET antivirus
- The ransomware not only encrypts data but also changes the pin
- Ransomware is spread through fake adobe flash player app
- A ransom amount of 0.0130 BTC is demanded to retrieve the data
A ransom amount of 0.0130 BTC (approximately USD 74) is demanded to retrieve the data.The only option for the user to retrieve their device other than paying ransom is factory reset, but files will be lost if not backed up properly.
Researchers said there is a possibility to bypass the pin in rooted devices if the device was in debugging mode before getting infected. “The user can connect to the device by ADB and remove the system file where the PIN is stored by Android. This operation unlocks the screen so that the user can access their device. Then, working in safe mode, the user can deactivate device administrator rights for the malware and uninstall it. In some cases, a device reboot is needed.” You may be interested in reading:Ransomware - How can you effectively tackle the challenges?To prevent your device from infection, do follow the instructions below:
- Always switch off “Allow installation from unknown sources” in security settings thereby restricting download apps from a third party and anonymous sources.
- Always backup your data regularly.
- Don’t download attachments from unknown sources.
- Always Use google play store to install apps, don’t use any third party app stores.
- Download apps from verified developers and check their app rating and download counts before installing an app.
- Verify app permission before installing an app.
- Install the best and updated antivirus/antimalware software which can detect and block these type of malware.
Read more on:New Locky Ransomware Variant Found which uses Ykcol Extension for Encrypting Files