1. /
  2. Security Response/
  3. Android.Simplocker


Risk Level 1: Very Low

June 5, 2014
July 24, 2014 12:18:52 PM
Infection Length:
Systems Affected:
Android.Simplocker is a Trojan horse for Android devices that may encrypt files on the compromised device. It then asks the user to pay in order to decrypt these files.

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: org.simplelocker
Version: 1.0
Name: simplelocker

Once installed, the application will display an icon of the Google Android mascot with the text "Sex xonix"

For more information see our blog:
Simplocker: First Confirmed File-Encrypting Ransomware for Android

Antivirus Protection Dates

  • Initial Rapid Release version June 5, 2014 revision 005
  • Latest Rapid Release version January 14, 2015 revision 007
  • Initial Daily Certified version June 5, 2014 revision 017
  • Latest Daily Certified version January 14, 2015 revision 020
  • Initial Weekly Certified release date June 11, 2014
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy


  • Damage Level: Medium
  • Payload: Encrypts files.


  • Distribution Level: Low
Writeup By: Roberto Sponchioni, Zhicheng Zeng

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver