s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.droidlock

📛 Threat Title

Malware family: DroidLock

Category: DroidLock First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.droidlock`. Printable name: DroidLock.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.droidlock VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.droidlock

IOC database

Type
domain
Value
apk.droidlock
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.droidlock

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.droidlock

References (1)

Remediations (10)

  • web:bladeintel.com

    DroidLock is delivered via phishing sites that trick users into installing a malicious app pretending to be, for example, a telecom provider or other familiar brand. The app is really a dropper that installs malware able to take complete control of the device by abusing Device Admin and Accessibility Services permissions.

  • web:botcrawl.com

    DroidLock is a newly identified Android malware family designed to lock users out of their own devices and threaten irreversible data loss unless a ransom is paid. Unlike traditional ransomware, DroidLock does not rely on file encryption or recovery keys. Instead, it asserts control at the operating system level. Once active, an attacker can lock the screen, change PINs or unlock patterns ...

  • web:cybersecurefox.com

    Security researchers at Zimperium have identified a new family of Android malware dubbed DroidLock . The threat stands out because it merges two dangerous capabilities: ransomware-style device locking and remote access trojan (RAT) functionality. Once installed, DroidLock can block access to the smartphone, demand a ransom, and at the same time give attackers near-complete control over the ...

  • web:cybersecuritynews.com

    A dangerous new malware called DroidLock is targeting Android users, particularly in Spanish-speaking regions, through phishing websites. This threat combines ransomware tactics with remote-control capabilities, posing a severe risk to users of personal and corporate devices.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Zimperium, DroidLock has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials, leading to a total takeover of the compromised device. It employs deceptive system update screens to trick victims and can stream and remotely control devices via VNC. The malware also exploits device administrator privileges to lock or erase data ...

  • web:thecyberexpress.com

    A new Android malware locks device screens and demands that users pay a ransom to keep their data from being deleted. Dubbed " DroidLock " by Zimperium researchers, the Android ransomware-like malware can also "wipe devices, change PINs, intercept OTPs, and remotely control the user interface, turning an infected phone into a hostile endpoint." The malware detected by the researchers ...

  • web:www.bleepingcomputer.com

    A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data.

  • web:www.malwarebytes.com

    Researchers have found Android malware that holds your files and your device hostage until you pay the ransom.

  • web:www.pcrisk.com

    Threats like DroidLock can typically be removed using reliable security software, including antivirus or anti- malware tools like Combo Cleaner, without losing your personal data. What are the biggest issues that malware can cause? Malware can carry out many harmful activities depending on its capabilities.

  • web:www.tomsguide.com

    The DroidLock malware supports 15 commands that let it send notifications, place an overlay on the screen, mute the device, reset it to factory settings, start the camera or uninstall apps.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.