1. Symantec/
  2. Security Response/
  3. Android.WannaLocker


Risk Level 1: Very Low

June 9, 2017
June 14, 2017 2:45:58 PM
Infection Length:
Systems Affected:
Android.WannaLocker is a Trojan horse for Android devices that encrypts files on the device's external storage and demands a payment to decrypt them.

Android package file
The Trojan may arrive as a package with the following characteristics:

APK: com.android.tencent.zdevs.bah
Version: 1.0

Once installed, the application will display an icon with Chinese text and an image of a character holding a bunch of red flowers.

Once opened, the application changes the icon to an close-up of a handshake with the text: Lycorisradiata. The application also changes the device's wallpaper to this image.

Antivirus Protection Dates

  • Initial Rapid Release version June 9, 2017 revision 021
  • Latest Rapid Release version August 1, 2017 revision 006
  • Initial Daily Certified version June 10, 2017 revision 001
  • Latest Daily Certified version August 1, 2017 revision 018
  • Initial Weekly Certified release date June 14, 2017
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Liang Yuan

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube