A new form of ransomware that actively locks out users by burrowing into a phone’s software has been detected by security researchers.
Named Lockerpin by researchers at security firm ESET, the malware alters a phone’s PIN lock function, stopping users from accessing their device unless they pay a ransom of $S500 ransom for allegedly viewing and harbouring forbidden pornographic material.
ESET says this is the first time they’ve ever detected such a function in malware, marking it as extremely dangerous for users.
However with Lockerpin, users have no effective way of regaining access to their device without root privileges or without some other form of security management solution installed, apart from a factory reset that would also delete all their data.
The ransomware is also able to worm its way in to obtaining and keeping Device Administrator privileges, meaning it is extremely tricky for users to uninstall, as when users attempt to deactivate Device Admin for the malware, they will fail because the Trojan will have registered a call-back function to reactivate the privileges when removal is attempted.
Similarly to when Device Administrator is first activated by the Trojan, if a removal attempt is made the Device Administrator window is again overlaid with a bogus window, which when selected effectively reactivates the elevated privileges.
“This is the first case in which we have observed this aggressive method in Android malware,” the researchers say.
ESET say that the only way to remove the PIN lock screen without a factory reset is when the device is rooted or has a MDM solution capable of resetting the PIN installed, both of which should allow the users to regain full functionality.
ESET says that over 75 percent of the infected devices are in the USA, reflecting a trend where Android malware writers are shifting from mostly targeting Russian and Ukrainian users to largely targeting victims in America, where arguably they can make bigger profits.
A study by ESET earlier in the year found that ransomware is an increasingly dangerous proposition for many UK businesses, with over a third of UK companies having either personally been held to ransom by hackers, or know someone that has had their networks infected by ransomware.
Security firm McAfee Labs also warned earlier this month that ransomware attacks grew 127 percent from Q2 2014 to Q2 2015, with McAfee attributing this to a number of fast-growing new families such as CTB-Locker and CryptoWall, both of which hit the headlines earlier this year.
Are you a security pro? Try our quiz!
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…
European Commission opens formal probe into TikTok after Romanian first-round elections annulled over Russian interference…