DroidLock Android malware with ransom lock and device-control capabilities
Malware Activity
Summary
Hide ▲
Show ▼
The DroidLock Android malware can lock victim screens for ransom and steal messages, call logs, contacts, and audio recordings, putting infected users at immediate extortion and privacy risk. It also supports complete device control through VNC sharing, overlay-based lock-pattern theft, and actions such as changing PINs or wiping data. The malware is distributed through malicious websites and fake applications that impersonate legitimate packages, with a dropper delivering the secondary payload. It targets Spanish-speaking users, while Play Protect blocks the threat on up-to-date devices.
Related Happenings
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware Activity
First: 27.05.2026 19:10
Last: 27.05.2026 19:10
Sources 1
About this happening:
The **Grandoreiro** and **BTMOB** trojans are being used in active campaigns against **Windows** and **Android** targets across **Europe** and **Latin America**, increasing the ri...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware ActivityAbout this happening: The **Grandoreiro** and **BTMOB** trojans are being used in active campaigns against **Windows** and **Android** targets across **Europe** and **Latin America**, increasing the ri...
BTMOB Android RAT no-code builder malware activity
Malware Activity
First: 26.05.2026 17:00
Last: 26.05.2026 17:00
Sources 1
About this happening:
The **BTMOB** Android RAT is spreading through **phishing campaigns** across **Brazil and beyond**, raising the risk of **custom payload delivery** and **remote device takeover**....
BTMOB Android RAT no-code builder malware activity
Malware ActivityAbout this happening: The **BTMOB** Android RAT is spreading through **phishing campaigns** across **Brazil and beyond**, raising the risk of **custom payload delivery** and **remote device takeover**....
Android 17 expands platform security and privacy protections
Security Tool/Service
First: 12.05.2026 20:00
Last: 12.05.2026 20:00
Sources 1
About this happening:
**Android 17** will add a broad set of **Google**-backed security and privacy controls next month, reducing exposure to **banking scam calls**, **device theft**, and **OTP theft**...
Android 17 expands platform security and privacy protections
Security Tool/ServiceAbout this happening: **Android 17** will add a broad set of **Google**-backed security and privacy controls next month, reducing exposure to **banking scam calls**, **device theft**, and **OTP theft**...
PromptSpy backdoor for Android with Gemini API automation
Malware Activity
First: 11.05.2026 16:02
Last: 11.05.2026 16:02
Sources 1
About this happening:
The **PromptSpy** backdoor for **Android** was highlighted for using **Gemini APIs** to automate device interaction, increasing the risk of unauthorized control on infected phones...
PromptSpy backdoor for Android with Gemini API automation
Malware ActivityAbout this happening: The **PromptSpy** backdoor for **Android** was highlighted for using **Gemini APIs** to automate device interaction, increasing the risk of unauthorized control on infected phones...
Perseus Android malware family actively distributed in the wild
Malware Activity
First: 19.03.2026 14:43
Last: 19.03.2026 14:43
Sources 1
About this happening:
The **Perseus** **Android malware** family is being actively distributed in the wild, putting infected devices at risk of **device takeover** and **financial fraud**. It spreads t...
Perseus Android malware family actively distributed in the wild
Malware ActivityAbout this happening: The **Perseus** **Android malware** family is being actively distributed in the wild, putting infected devices at risk of **device takeover** and **financial fraud**. It spreads t...
Timeline
-
10.12.2025 23:53 2 articles · 5mo ago
Zimperium discloses DroidLock Android malware
Initial DisclosureZimperium identifies DroidLock as a newly discovered Android malware that targets Spanish-speaking users through malicious websites and fake apps, uses a dropper to install a secondary payload, requests Device Admin and Accessibility Services permissions, and can lock screens for ransom, steal text messages, call logs, contacts, and audio recordings, change PIN/password/biometric data, erase files, and control devices through VNC and overlay-based lock-pattern theft; up-to-date devices are blocked by Play Protect.
Show sources
- New DroidLock malware locks Android devices and demands a ransom — www.bleepingcomputer.com — 10.12.2025 23:53
- New DroidLock malware locks Android devices and demands a ransom — www.bleepingcomputer.com — 10.12.2025 23:53