{"id":3598,"date":"2019-08-05T15:00:42","date_gmt":"2019-08-05T12:00:42","guid":{"rendered":"https:\/\/blog.eset.ee\/?p=3598"},"modified":"2019-08-05T14:33:30","modified_gmt":"2019-08-05T11:33:30","slug":"eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/","title":{"rendered":"ESET researchers discover new Android ransomware that tries to spread all around"},"content":{"rendered":"\n<p>Android ransomware may have been on the decline since 2017 \u2013 but recently,\nESET researchers discovered a new ransomware family, Android\/Filecoder.C. Using\nvictims\u2019 contact lists, it attempts to spread further via SMSes with malicious\nlinks. <\/p>\n\n\n\n<p>The new ransomware was seen\ndistributed via porn-related topics on Reddit. The malicious profile used in\nthe ransomware-distributing campaign was reported by ESET, but is still active.\nFor a short period of time, the campaign had also run on the \u201cXDA developers\u201d\nforum, a forum for Android developers; based on ESET\u2019s report, the operators\nremoved the malicious posts. <\/p>\n\n\n\n<p><em>\u201cThe\ncampaign we discovered is small and rather amateurish. However, if the\ndistribution becomes more advanced, this new ransomware could become a serious\nthreat,\u201d<\/em>\ncomments Luk\u00e1\u0161 \u0160tefanko, the ESET researcher who led the investigation. <\/p>\n\n\n\n<p>The new ransomware is\nnotable for its spreading mechanism. Before it starts encrypting files, it sends\na batch of text messages to every address in the victim\u2019s contact list, luring\nthe recipients to click on a malicious link leading to the ransomware\ninstallation file. <em>\u201cIn theory, this can\nlead to a flood of infections \u2013 more so that the malware has 42 language\nversions of the malicious message. Fortunately, even non-suspecting users must notice\nthat the messages are poorly translated, and some versions do not seem to make\nany sense,\u201d<\/em> comments Luk\u00e1\u0161 \u0160tefanko. <\/p>\n\n\n\n<p>Besides its non-traditional\nspreading mechanism, Android\/Filecoder.C has a few anomalies in its encryption.\nIt excludes large archives (over 50 MB) and small images (under 150 kB), and\nits list of \u201cfiletypes to encrypt\u201d contains many entries unrelated to Android, while\nalso lacking some of the extensions typical for Android. <em>\u201cApparently, the list has been copied from the notorious WannaCry\nransomware,\u201d<\/em> observes \u0160tefanko.<\/p>\n\n\n\n<p>There are also other intriguing\nelements to the unorthodox approach that the developers of this malware have\nused. Unlike typical Android ransomware, Android\/Filecoder.C doesn\u2019t prevent\nthe user from accessing the device by locking the screen. Furthermore, the\nransom is not set as a hardcoded value; instead, the amount that the attackers request\nin exchange for the promise of decrypting the files is created dynamically using\nthe UserID assigned by the ransomware to the particular victim. This process\nresults in a unique ransom amount, falling in the range of 0.01-0.02 BTC. <\/p>\n\n\n\n<p><em>\u201cThe trick with a unique ransom is novel: we\nhaven\u2019t seen it before in any ransomware from the Android ecosystem,\u201d <\/em>says \u0160tefanko<em>. \u201cIt is probably meant to assign payments\nto victims. This task is typically solved by creating a unique Bitcoin wallet\nfor every encrypted device. In this campaign, we\u2019ve only seen one Bitcoin wallet\nbeing used.\u201d<\/em> <\/p>\n\n\n\n<p>According to Luk\u00e1\u0161 \u0160tefanko,\nusers with devices protected by ESET Mobile Security are safe from this threat.\n\u201c<em>They receive a warning about the\nmalicious link; should they ignore the warning and download the app, the\nsecurity solution will block it<\/em>.\u201d<\/p>\n\n\n\n<p>This discovery shows that\nransomware still poses a threat to Android mobile devices. To stay safe, users\nshould stick to basic security principles:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Keep your devices up to date; ideally, set them to patch and update\n     automatically so that you stay protected.<\/li><li>If possible, stick with Google Play or other reputable app stores.\n     These markets may not be completely free from malicious apps, but you have\n     a fair chance of avoiding them.<\/li><li>Prior to installing any app, check its ratings and reviews. Focus on\n     the negative ones, as they often come from legitimate users, while\n     positive feedback is often crafted by the attackers.<\/li><li>Focus on the permissions requested by the app. If they seem\n     inadequate for the app\u2019s functions, avoid downloading the app.<\/li><li>Use a reputable mobile security solution to protect your device.<\/li><\/ul>\n\n\n\n<p>For more information read\nWe Live Security <a href=\"https:\/\/www.welivesecurity.com\/2019\/07\/29\/android-ransomware-back\/\">blog<\/a>.&nbsp; <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Android ransomware may have been on the decline since 2017 \u2013 but recently, ESET researchers discovered a new ransomware family, Android\/Filecoder.C. Using victims\u2019 contact lists, it attempts to spread further via SMSes with malicious links. The new ransomware was seen distributed via porn-related topics on Reddit. The malicious profile used in the ransomware-distributing campaign was<\/p>\n","protected":false},"author":5,"featured_media":3602,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[168],"tags":[],"class_list":["post-3598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>ESET researchers discover new Android ransomware that tries to spread all around - ESET Eesti Blogi<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ESET researchers discover new Android ransomware that tries to spread all around\" \/>\n<meta property=\"og:description\" content=\"Android ransomware may have been on the decline since 2017 \u2013 but recently, ESET researchers discovered a new ransomware family, Android\/Filecoder.C. Using victims\u2019 contact lists, it attempts to spread further via SMSes with malicious links. The new ransomware was seen distributed via porn-related topics on Reddit. The malicious profile used in the ransomware-distributing campaign was\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/\" \/>\n<meta property=\"og:site_name\" content=\"ESET Eesti Blogi\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/antiviirus\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-05T12:00:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"ESET Blog\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ESET Blog\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/\"},\"author\":{\"name\":\"ESET Blog\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/#\\\/schema\\\/person\\\/876cf293277fc0b2ae2f4395fffe4c88\"},\"headline\":\"ESET researchers discover new Android ransomware that tries to spread all around\",\"datePublished\":\"2019-08-05T12:00:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/\"},\"wordCount\":629,\"image\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.eset.ee\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/android_ransomware_eset.png\",\"articleSection\":[\"ransomware\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2019\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/\",\"url\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/\",\"name\":\"ESET researchers discover new Android ransomware that tries to spread all around - ESET Eesti Blogi\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.eset.ee\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/android_ransomware_eset.png\",\"datePublished\":\"2019-08-05T12:00:42+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/#\\\/schema\\\/person\\\/876cf293277fc0b2ae2f4395fffe4c88\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.eset.ee\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/android_ransomware_eset.png\",\"contentUrl\":\"https:\\\/\\\/blog.eset.ee\\\/wp-content\\\/uploads\\\/2019\\\/08\\\/android_ransomware_eset.png\",\"width\":1200,\"height\":628},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ESET researchers discover new Android ransomware that tries to spread all around\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/\",\"name\":\"ESET Eesti Blogi\",\"description\":\"Uudised IT maailmast\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/#\\\/schema\\\/person\\\/876cf293277fc0b2ae2f4395fffe4c88\",\"name\":\"ESET Blog\",\"sameAs\":[\"http:\\\/\\\/eset.ee\"],\"url\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/author\\\/allankinsigo\\\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.eset.ee\\\/et\\\/en\\\/2019\\\/08\\\/05\\\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\\\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"ESET EESTI\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"ESET researchers discover new Android ransomware that tries to spread all around - ESET Eesti Blogi","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/","og_locale":"en_US","og_type":"article","og_title":"ESET researchers discover new Android ransomware that tries to spread all around","og_description":"Android ransomware may have been on the decline since 2017 \u2013 but recently, ESET researchers discovered a new ransomware family, Android\/Filecoder.C. Using victims\u2019 contact lists, it attempts to spread further via SMSes with malicious links. The new ransomware was seen distributed via porn-related topics on Reddit. The malicious profile used in the ransomware-distributing campaign was","og_url":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/","og_site_name":"ESET Eesti Blogi","article_publisher":"http:\/\/www.facebook.com\/antiviirus","article_published_time":"2019-08-05T12:00:42+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png","type":"image\/png"}],"author":"ESET Blog","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ESET Blog","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#article","isPartOf":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/"},"author":{"name":"ESET Blog","@id":"https:\/\/blog.eset.ee\/et\/en\/#\/schema\/person\/876cf293277fc0b2ae2f4395fffe4c88"},"headline":"ESET researchers discover new Android ransomware that tries to spread all around","datePublished":"2019-08-05T12:00:42+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/"},"wordCount":629,"image":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png","articleSection":["ransomware"],"inLanguage":"en-US","copyrightYear":"2019","copyrightHolder":{"@id":"https:\/\/blog.eset.ee\/et\/#organization"}},{"@type":"WebPage","@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/","url":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/","name":"ESET researchers discover new Android ransomware that tries to spread all around - ESET Eesti Blogi","isPartOf":{"@id":"https:\/\/blog.eset.ee\/et\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#primaryimage"},"image":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png","datePublished":"2019-08-05T12:00:42+00:00","author":{"@id":"https:\/\/blog.eset.ee\/et\/en\/#\/schema\/person\/876cf293277fc0b2ae2f4395fffe4c88"},"breadcrumb":{"@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#primaryimage","url":"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png","contentUrl":"https:\/\/blog.eset.ee\/wp-content\/uploads\/2019\/08\/android_ransomware_eset.png","width":1200,"height":628},{"@type":"BreadcrumbList","@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.eset.ee\/et\/en\/"},{"@type":"ListItem","position":2,"name":"ESET researchers discover new Android ransomware that tries to spread all around"}]},{"@type":"WebSite","@id":"https:\/\/blog.eset.ee\/et\/en\/#website","url":"https:\/\/blog.eset.ee\/et\/en\/","name":"ESET Eesti Blogi","description":"Uudised IT maailmast","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.eset.ee\/et\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.eset.ee\/et\/en\/#\/schema\/person\/876cf293277fc0b2ae2f4395fffe4c88","name":"ESET Blog","sameAs":["http:\/\/eset.ee"],"url":"https:\/\/blog.eset.ee\/et\/en\/author\/allankinsigo\/"},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.eset.ee\/et\/en\/2019\/08\/05\/eset-researchers-discover-new-android-ransomware-that-tries-to-spread-all-around\/#local-main-organization-logo","url":"","contentUrl":"","caption":"ESET EESTI"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/3598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=3598"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/3598\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/3602"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=3598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=3598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=3598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}