Sunday, April 27, 2025
HomeRansomwareMobile Ransomware "LeakerLocker" Found in Play store Apps that Encrypt and Send...

Mobile Ransomware “LeakerLocker” Found in Play store Apps that Encrypt and Send Personal Data on a Remote Server

Published on

SIEM as a Service

Follow Us on Google News

Mobile Ransomware called “LeakerLocker” found in 3 Google Play store Applications that encrypt the Victims Personal information such as Contact List that send it Across Remote server and Exposed it.

Google PlayStore Malware’s are Evolving day by day which has to threaten Millions of Peoples and few weeks before LeakerLocker were Already found Another Android App.

3 Dangerous Android Applications “Wallpapers Blur HD”, “Booster & Cleaner Pro”, and “Calls Recorder” were Found in Google Play store that carried this LeakerLcker Ransomware.

- Advertisement - Google News

This Ransomware Detected as  ANDROIDOS_LEAKERLOCKER.HRX  and also found some similar apps that had the same name which has similar Functionality of LeakerLocker.

Trend Micro  Researchers said, While there is no evidence that these applications were made by the same person, it is highly possible that a single developer created them, given that they all carry the ransomware.

Also Read    Machine learning system to create invisible malware’s – gym-malware

LeakerLocker Infection Flow

Initially, once User Download the Malicious Apps which is having Embedded LeakerLocker Ransomware that steals Personal information of the Victims.

Before Proceeding App Performs Various Checks and Communicate with C & C server later it Drops the Malware on the Victims Machine.Ransomware

Infection Flow of LeakerLocker

An Application called “Calls Recorder” which was found in Google PlayStore that initially gather the numbers of contacts, photos, and recent phone calls to check whether those numbers are larger than the previously defined numbers.

But Malicious Code will not Execute if there will not enough contacts, photos and Phone calls that less than defined.

Evade the Dynamic Malware Detection, this Application Delayed 15 Minutes to Execution of its Malicious code into the victims Mobile.

Later “Calls Recorder” check the WiFi Connection of the weather user enabled WiFi Connection or not and disable it before checking the Mobile data connection.

This Malicious code will not perform if mobile data connection will not be enabled.later it will restore the WIFi Connection.

Ransomware

Malicious Calls Recorder App

Installed malware from Google Play store will perform only perform its Malicious Activities by only using its installation Method.

Trend Micro said, After all the required checks pass, “Calls Recorder” will send a request to hxxp://updatmaster.top/click[.]php. If the request is successful, it will send a broadcast that triggers the malware.
 Once the receiver receives the broadcast, it will launch another Java class named x.ld.Ld. After the related broadcast is sent, the app loads and x.ld.Ld requests data from hxxp://176.9.18.91 to get further instructions.
 

The server will Respond With JAR Files that downloaded and Configured. According to Researchers Analyse, server response, “Calls Recorder” will download two JAR files — “u.jar” and “x.awvw.Awvw.jar”, as well as their configurations. “Calls Recorder” will then load, execute, and remove these two JAR files.

Finally “support.jar” opens the Web page view that contains the information showing details of contacts, phone calls, SMS, and other potentially sensitive information.

Ransomware

LeakerLocker Ransomware Alert

Trend Micro Said, We did not actually find any code indicating that LeakerLocker will actually do what it threatens to do. However, tapping into the user’s fear of being exposed can be an effective extortion tactic. While traditional file encrypting Ransomware does damage by actually encrypting files, LeakerLocker works on a deeper psychological level.

Image Source: Trend Micro

Also Read   Mobile Banking Malware “Svpeng” Working as a Keylogger and Steals Contacts and Call Logs

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

DragonForce and Anubis Ransomware Gangs Launch New Affiliate Programs

Secureworks Counter Threat Unit (CTU) researchers have uncovered innovative strategies deployed by the DragonForce...

Threat Actors Target Organizations in Thailand with Ransomware Attacks

Thailand is experiencing a significant escalation in ransomware attacks, with both state-sponsored advanced persistent...

Verizon DBIR Report: Small Businesses Identified as Key Targets in Ransomware Attacks

Verizon Business's 2025 Data Breach Investigations Report (DBIR), released on April 24, 2025, paints...