Beware of Android Coronavirus Tracker app that Lock’s Your Device & Asks Ransom Payment

Cybercriminals using the Coronavirus outbreak to trick users into installing malicious corona virus-related apps.

In the current panic, situation users are most vulnerable to apps like Coronavirus Trackers, symptoms identification, maps, etc.

Malicious Coronavirus Tracker

Security researchers from Domaintools observed a malicious Coronavirus tracker app that locks the user’s Android device and asks for a ransom payment.

The good news is that the malware not through the official Google play store, distributed through the website coronavirusapp[.]site.

The app claims to have a real-time Coronavirus outbreak tracker available via an app download. Once the app installed in the front end it shows tracking and statistical information about COVID-19 including the heatmap.

Heatmap

But in the background, it is poisoned with ransomware, which is previously unseen, the app titled “CovidLock”.

It locks the phone by forcing a password change and the threat actors request $250 in bitcoin in 48 hours to unlock the phone.

CovidLock is a new ransomware that launches a lock-screen attack while installing the app it asks for device administrator permissions if done it locks the screen and encrypts the storage.

Request Permission

Also, the ransom note threatens that all your contacts, pictures and videos are getting deleted if the ransom note was not paid.

Ransom note

The ransom note includes a Bitcoin wallet ID, where users are forced to pay the ransom, the bitcoin address shows no victims currently paid the ransom.

Related Read

CoronaVirus Cyber Attack Panic – Threat Actors Targets Victims Worldwide

Chinese APT Hackers Exploit MS Word Bug to Drop Malware Via Weaponized Coronavirus Lure Documents

How Can The Coronavirus (COVID-19) Disrupt Cybersecurity Operations?

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hunters International Claims Tata Technologies Cyberattack

Multinational engineering and technology services firm Tata Technologies has reportedly fallen victim to a significant…

3 minutes ago

Authorities Seize $31 Million Linked to Crypto Exchange Hack

U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance decentralized…

23 minutes ago

Google, Meta, and Apple Power the World’s Biggest Surveillance System

Imagine a government that tracks your daily movements, monitors your communications, and catalogs your digital…

28 minutes ago

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…

2 hours ago

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…

2 hours ago

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…

5 hours ago