1. /
  2. Security Response/
  3. Android.Simplocker

Android.Simplocker

Risk Level 1: Very Low

Discovered:
June 5, 2014
Updated:
July 24, 2014 12:18:52 PM
Type:
Trojan
Infection Length:
Varies
Systems Affected:
Android
Android.Simplocker is a Trojan horse for Android devices that may encrypt files on the compromised device. It then asks the user to pay in order to decrypt these files.



Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: org.simplelocker
Version: 1.0
Name: simplelocker


Installation
Once installed, the application will display an icon of the Google Android mascot with the text "Sex xonix"



For more information see our blog:
Simplocker: First Confirmed File-Encrypting Ransomware for Android

Antivirus Protection Dates

  • Initial Rapid Release version June 5, 2014 revision 005
  • Latest Rapid Release version June 5, 2014 revision 005
  • Initial Daily Certified version June 5, 2014 revision 017
  • Latest Daily Certified version June 5, 2014 revision 017
  • Initial Weekly Certified release date June 11, 2014
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Payload: Encrypts files.

Distribution

  • Distribution Level: Low
Writeup By: Roberto Sponchioni, Zhicheng Zeng

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver