Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

10/13/2017
04:55 PM
50%
50%

DoubleLocker Delivers Unique Two-Punch Hit to Android

Combines Android ransomware with capability to change users device PINs.

Android users downloading a fake Adobe Flash Player from a malicious website may find themselves victimized by a unique strain of Android ransomware called DoubleLocker, ESET researchers disclosed today.

DoubleLocker, which was discovered in the wirld in August, will not only encrypt users' Android device data, but it takes the additional step of changing the device PIN, according to Lukas Stefanko, ESET malware researcher.

"The most interesting thing here is that it uses a dangerous combination of three aspects we have not seen before: accessibility services, which performs a click on the user's behalf; it encrypts data; and it can reset a PIN for a user's device," Stefanko told Dark Reading.

DoubleLocker was created based on mobile banking malware that misuses accessibility services to gain control over the infected device.

The bogus Adobe Flash player, asks to activate a bogus version of "Google Play Service" through the malware's accessibility service. 

"There are no exploited vulnerabilities, they're just using the system as it is designed," Stefanko says.

Once DoubleLocker secures accessibility permissions, it leverages them to snag administrator rights for the device and establishes itself as the default Home application without the user's approval.

As the default home app, or launcher, DoubleLocker is activated after the user presses the home button. It then changes the PIN and sets it to a random value that is not stored on the device or sent out, according to ESET's report. As a result, neither the user or security teams can recover the PIN. If a user pays the ransom, the attacker remotely resets the PIN and unlocks the device.

DoubleLocker can also act as traditional ransomware and encrypt files in the primary storage directory on the device. Users will realize they have been attacked if they find the ".cryeye" filename extension, according to ESET.

To Pay or Not to Pay

DoubleLocker demands 0.0130 Bitcon, or roughly $54, in ransom, and victims are ordered to make a payment within 24 hours. If they do so, they get their data back.

Meanwhile, there is a way to reset a hijacked PIN, according to ESET's report.

Devices that have not been rooted and are without a mobile device management system that can reset the PIN can be restored with a factory reset. While that will remove the PIN lock screen, it will also delete whatever data was on the device.

For devices that are rooted and have debugging enabled in the settings, a user can connect the device by the Android Debug Bridge (ADB) and remove the file where the PIN is stored, ESET advises.

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Related Content:

 

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
johnp140
100%
0%
johnp140,
User Rank: Apprentice
2/16/2018 | 2:31:36 AM
DoubleLocker
Malware specialists have recently found another variant of Android infection that may fill in as a saving money trojan and versatile ransomware. Known as DoubleLocker, malware, is by all accounts identified with Erricson Routers Customer Service the Svpeng keeping money trojan. Be that as it may, this pernicious program is by all accounts more advanced.
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19071
PUBLISHED: 2019-11-18
A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19072
PUBLISHED: 2019-11-18
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
CVE-2019-19073
PUBLISHED: 2019-11-18
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, ...
CVE-2019-19074
PUBLISHED: 2019-11-18
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
CVE-2019-19075
PUBLISHED: 2019-11-18
A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.