Friday, January 31, 2025
HomeMalwareA Mobile Ransomware Called "LeakerLocker" Found in Google Play Store Which ...

A Mobile Ransomware Called “LeakerLocker” Found in Google Play Store Which Leaks Phone’s Sensitive Information and Demand to Pay

Published on

SIEM as a Service

Follow Us on Google News

Mobile Ransomware called LeakerLocker Found in Google Playstore which infect the Android Mobile user and steals the information such as contact Phone numbers, Phone call History, personal images and Email texts etc.

This Ransomware will be Encrypt the file instead of that, this malware Demand a payment to prevent the attacker from spreading a victim’s private information.

Once LeakerLocker Ransomware attacks the Victims, it takes unauthorized backup of the victims personal information and that could be leaked if victims denied paying the demanded ransom Payment.

Source : McAFee

Once Victim infected, its asks to inputs a credit card number and clicks “Pay,” the code send a request to the payment URL with the card number as a parameter.

After payment successfully initiated it gives a reply that,“our [sic] personal data has been deleted from our servers and your privacy is secured.” If not successful, it shows “No payment has been made yet. Your privacy is in danger.” 

Malicious Applications in PlayStore

McAfee  Researchers Found 2 Malicious applications in Google Playstore which infected by this  LeakerLocker Ransomware.

1.Wallpapers Blur HD

This Malicious Wallpaper Application Found Google Play Store  that users always complains that , Playstorewhenever installing the Application it always Asking some sensitive Permissions such as calls, reading and sending SMS, access to contacets, etc.

This Applications hide a Malicious Payload inside of the Apps. once install into the Victims Machine it automatically execute the payload and force the victims to allow all the sensitive permisssion.

According to MacFee ,It has been downloaded between 1,000 and 5,000 times. Its rating is 4.5, much higher than Wallpaper’s 3.6.

Also Read  Android Trojan Called “SpyDealer” Spying on More Than 40 Apps Including Facebook, WhatsApp, Skype,Telegram

Booster & Cleaner Pro

This Malicious Applications downloaded between 1,000 and 5,000 times iPlay storeand it have some positive reviews.

Positive Rewviews are not a safety indicator because fake reviews are very common in fraudulent apps.

“At first execution, the malware displays typical functions of Android boosters. Due to the nature of this kind of application, users could be more willing to allow access to almost any permission”

LeakerLocker locks the home screen and accesses private information in the background thanks to its victims granting permissions at installation time.

McaFee Reported this Malicious Activities to Google and Belives that this Applications will be removed form PlayStore as soon as Possible.

Also Read Android Malware Called “CopyCat” Infected Around 14 Million Android Devices and Gained over $1.5 Million

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

Hackers Impersonate Top Tax Firm with 40,000 Phishing Messages to Steal Credentials

Proofpoint researchers have identified a marked increase in phishing campaigns and malicious domain registrations...

Lazarus Group Drop Malicious NPM Packages in Developers Systems Remotely

In a recent discovery by Socket researchers, a malicious npm package named postcss-optimizer has...