In terms of security, ransomware and RATs (remote access Trojans) are a true nightmare to organizations and stand-alone users. It’s to no one’s surprise that Kaspersky Lab has defined ransomware attacks an epidemic. As pointed out by security researcher Andrey Pozhogin, no user is safe. Both the consumer and the business can become a victim of ransomware.
Moreover, ransom attacks are about to go out of hand with the rising of Android and cloud storage ransomware.
A New Version of Android/Lockerpin.A Ransom Malware
A new malicious Android attack has indeed been detected just recently. It has been spreading with the help of an adult application named Porn Droid. Once the device is infected, the user’s screen PIN will be changed, and a ransom will be demanded. The amount of the ransom is $500 and €450.
Infection Path
The new strand of Android/Lockerpin.A ransomware is distributed via applications downloaded from unsafe locations such as torrents and third-party pages. Any app out of the Google Play store may have been employed by cyber criminals to spread ransomware or other forms of mobile threats.
Once the app is installed on the device, Lockerpin.A will ask for admin rights while camouflaging as an update. As you can see, the mobile ransomware is not as innovative as one might think but is as damaging as ransomware can be.
Porno-themed schemes are not anything new, and we have seen many attempts on behalf of cyber criminals. What is more, that is not the only ‘adult’ ransomware detected in September 2015. The same ‘style’ has been observed by the security team at Zscaler. They discovered an application dubbed Adult Player, which takes images of victims and blackmails them by using their image in the ransom message.
How to Rid Your Device from Android/Lockerpin.A
Researchers point out that the only way to remove the ransom message is by booting your phone in Safe Mode and uninstalling the malicious software.
Another thing to be tried is using the Android Debug Bridge. ADB is a versatile command line tool that lets users communicate with an emulator instance or connected Android-powered device.
Once the ransomware is deleted from the device, resetting it to factory settings is still needed to rid of the ‘unknown’ PIN issue.
We have also compiled several easy-to-follow steps for mobile device users.
Preparation before removal of malware.
Before starting the actual removal process, we recommend that you do the following preparation steps.
- Turn off your phone until you know how bad is the virus infection.
- Open these steps on another, safe device.
- Make sure to take out your SIM card, as the virus could corrupt it in some rare cases.
Step 1: Shut Down your phone to win some time
Shutting down your phone can be done by pressing and holding its power button and choosing shut down.
In case the virus does not let you do this, you can also try to remove the battery.
In case your battery is non-removable, you can try to drain it as fast as possible if you still have control over it.
Notes: This gives you time to see how bad the situation is and to be able to take out your SIM card safely, without the numbers in it to be erased. If the virus is on your computer, it is espeically dangerous to keep the sim card there.
Step 2: Turn on Safe Mode of your Android device.
For most Android devices, switching to Safe Mode is the same. Its done by following these mini-steps:
Step 3: Eliminate the App that Your Believe is the Virus
Usually Android viruses get masked in the form of applications. To eliminate apps, follow these mini-steps:
Step 4: Find Hidden Virus Files on Your Android Phone and Remove Them
Simply locate the virus and hold-tap on the virus file to delete it.