1. /
  2. Security Response/
  3. Android.Scartibro


Risk Level 1: Very Low

August 7, 2014
August 8, 2014 9:57:12 AM
Infection Length:
Systems Affected:
Android.Scartibro is a Trojan horse for Android devices that locks the compromised device and asks the user to pay in order to unlock it.

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.android.locker
Name: Norton Internet Security

Once installed, the application will display an icon with the text of "Norton Internet Security" below a yellow circle with a black check mark inside of it, attempting to mimic the appearance of the Norton logo.

Note: Malware authors often mimic legitimate brands in order to lure users into trusting and installing malicious applications.

Antivirus Protection Dates

  • Initial Rapid Release version August 7, 2014 revision 019
  • Latest Rapid Release version December 3, 2014 revision 049
  • Initial Daily Certified version August 7, 2014 revision 025
  • Latest Daily Certified version December 4, 2014 revision 037
  • Initial Weekly Certified release date August 13, 2014
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy


  • Damage Level: Medium
  • Payload: Locks the device and demands a ransom to unlock it.


  • Distribution Level: Low
Writeup By: Andrea Lelli

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report
Symantec DeepSight Screensaver