New Ransomware Attacks Android Devices Encrypts Photos and Videos Posing as COVID-19 Tracing App

A new ransomware strain dubbed CryCryptor targeting Android users, particularly users in Canada posing as an official COVID-19 tracing app from Health Canada.

The CryCryptor is a new ransomware based on the open-source ransomware CryDroid published on Jun 11, 2020.

The malicious campaign started after the Canadian government announced the official tracing app, according to sources the app is still in the testing phase and to be live possibly next month.

Malicious Ransomware Campaign

Security researchers from ESET observed that malicious COVID-19 tracing app distributed using two third-party websites and not through Google Play.

Once the malicious app launched in the device it seeks permission to access files on the device, once permission provided it encrypts files with certain extensions.

The extensions include txt, jpg, BMP, png, pdf, doc, Docx, ppt, pptx, avi, Xls, vcf, pdf, and db files.

Extensions Encrypted

The ransomware encrypts files only and not lock the device, it leaves a “readme” file in every directory with encrypted files that have the attacker’s email address.

The good news here is that we are having a decryption tool available for this ransomware, ESET researchers discovered a bug with the malicious app which allows them to create a decryption tool.

Researchers published a video that shows the process of encryption and decryption.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Also Read:

COVID-19 Research Organizations Attacked by Chinese Hackers Group

Trickbot Malware Campaign Targets users with COVID-19 Themed Malspam

Guru Baran

Recent Posts

Dell, HP, & Lenovo System Found Using Outdated OpenSSL Cryptographic Library

The cybersecurity researchers at Binarly recently discovered that outdated versions of the OpenSSL cryptographic library…

1 day ago

Chrome Zero-Day Bug Actively Exploited in the Wild – Google Emergency Update!

The eighth zero-day vulnerability used in attacks this year has been fixed by Google in…

2 days ago

Operation HAECHI III – INTERPOL Arrested 1000 Cyber Criminals & Seized $130 Million

Recently, there have been almost 1000 arrests made as a result of a police operation…

4 days ago

Hackers Rewritten The RansomExx Ransomware in Rust Language To Evade Detection

There has recently been a discovery made by IBM Security X-Force Threat Researchers regarding a…

5 days ago

Web Application Penetration Testing Checklist – A Detailed Cheat Sheet

Web Application Pentesting is a method of identifying, analyzing and Report the vulnerabilities which are…

6 days ago

Chrome Extension Deploy Windows Malware to Steal Cryptocurrency and Clipboard Contents

In order to steal cryptocurrency and clipboard contents, ViperSoftX was detected by the security analysts…

7 days ago