LeakerLocker Android Malware Is Mobile Ransomware Without The Encryption

Android mobile ransomware that acts without encryption has been discovered by cyber security firm McAfee, noting the malware extorts payments out of its victims by threatening to spread private information.

Dubbed LeakerLocker, the ransomware lurks behind two apps on Google’s Play Store; Wallpapers Blur HD and Booster & Cleaner Pro, both of which are supposedly well-rated apps that have been downloaded thousands of times.

Google has been alerted to the threat by the McAfee Mobile Malware Research team and is currently investigating it.

LeakerLocker ransomware

Through exploiting the higher level of permissions a user allows the infected apps due to the services they offer such as boosting performance and managing apps, LeakerLocker starts its malicious activity as soon at the infected app is booted.

“LeakerLocker locks the home screen and accesses private information in the background thanks to its victims granting permissions at installation time. It does not use an exploit or low-level tricks but it can remotely load .dex code from its control server so the functionality can be unpredictable, extended, or deactivated to avoid detection in certain environments,” explained McAfee’s threat advisory.

“Not all the private data that the malware claims to access is read or leaked. The ransomware can read a victim’s email address, random contacts, Chrome history, some text messages and calls, pick a picture from the camera, and read some device information.”

From the infection point onward, LeakerLocker displays a random collection of information in JavaScript to convince the victims that it has access to their private data such as browsing history and contacts, and threatens to leak them unless a “modest ransom” to the sum of $50 (£38) is paid via credit card in under 72 hours.

Once a payment is completed a message displays that the private information has been deleted from the cyber criminal’s servers.

However, McAfee suggests victims make no such payments: “We advise users of infected devices to not pay the ransom: Doing so contributes to the proliferation of this malicious business, which will lead to more attacks. Also, there is no guarantee that the information will be released or used to blackmail victims again.”

LeakerLocker may not be the most dangerous of ransomware but it certainly attempted to play on the paranoia people have developed around their personal information.

It also highlights that mobile malware remains a major threat to the Android platform, though Google is pushing to mitigate such threats with Android O.

Are you a security pro? Try our quiz!

Roland Moore-Colyer

As News Editor of Silicon UK, Roland keeps a keen eye on the daily tech news coverage for the site, while also focusing on stories around cyber security, public sector IT, innovation, AI, and gadgets.

View Comments

  • Unfortunate its the fundamental design of Android that is at fault here, permissions should be required on a run time basis not on an install basis (but that is useful as an extra) - and should be switchable at any time per application - its fundamental security

Recent Posts

TikTok Viewed As Chinese Influence Tool By Most Americans – Poll

Most people in the United States view TikTok as a Chinese influence tool a poll…

12 hours ago

Ofcom Confirms OnlyFans Investigation Over Age Verification

UK regulator confirms it is investigating whether OnlyFans is doing enough to prevent children accessing…

12 hours ago

Ex Google Staff Fired Over Israel Protest File NLRB Complaint

Dismissed staff file complaint with a US labor board, and allege Google unlawfully terminated their…

14 hours ago

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

15 hours ago

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

16 hours ago

Binance’s Changpeng Zhao Sentenced To Four Months In Prison

US judge sentences Binance founder, Changpeng Zhao, to four months in prison for ignoring money…

19 hours ago