1. Symantec/
  2. Security Response/
  3. Android.WannaLocker

Android.WannaLocker

Risk Level 1: Very Low

Discovered:
June 9, 2017
Updated:
June 14, 2017 2:45:58 PM
Type:
Trojan
Infection Length:
Varies
Systems Affected:
Android
Android.WannaLocker is a Trojan horse for Android devices that encrypts files on the device's external storage and demands a payment to decrypt them.



Android package file
The Trojan may arrive as a package with the following characteristics:

APK: com.android.tencent.zdevs.bah
Version: 1.0


Installation
Once installed, the application will display an icon with Chinese text and an image of a character holding a bunch of red flowers.



Once opened, the application changes the icon to an close-up of a handshake with the text: Lycorisradiata. The application also changes the device's wallpaper to this image.


Antivirus Protection Dates

  • Initial Rapid Release version June 9, 2017 revision 021
  • Latest Rapid Release version August 1, 2017 revision 006
  • Initial Daily Certified version June 10, 2017 revision 001
  • Latest Daily Certified version August 1, 2017 revision 018
  • Initial Weekly Certified release date June 14, 2017
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Liang Yuan

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube