Android ransomware is back July 29, 2019/in News /by

New Post Public Reply Private Reply Replies (0) Message Board
CyberC
561
Android ransomware is back
July 29, 2019/in News /by Lukas Stefanko

ESET researchers discover a new Android ransomware family that attempts to spread to victims’ contacts and deploys some unusual tricks

After two years of decline in Android ransomware, a new family has emerged. We have seen the ransomware, detected by ESET Mobile Security as Android/Filecoder.C, distributed via various online forums. Using victims’ contact lists, it spreads further via SMS with malicious links. Due to narrow targeting and flaws in both execution of the campaign and implementation of its encryption, the impact of this new ransomware is limited. However, if the developers fix the flaws and the operators start targeting broader groups of users, the Android/Filecoder.C ransomware could become a serious threat.

Android/Filecoder.C has been active since at least July 12th, 2019. Within the campaign we discovered, Android/Filecoder.C has been distributed via malicious posts on Reddit and the “XDA Developers” forum, a forum for Android developers. We reported the malicious activity to XDA Developers and Reddit. The posts on the XDA Developers forum were removed swiftly; the malicious Reddit profile was still up at the time of publication.

Android/Filecoder.C spreads further via SMS with malicious links, which are sent to all contacts in the victim’s contact list.

After the ransomware sends out this batch of malicious SMSes, it encrypts most user files on the device and requests a ransom. Due to flawed encryption, it is possible to decrypt the affected files without any assistance from the attacker.

Users with ESET Mobile Security receive a warning about the malicious link; should they ignore the warning and download the app, the security solution will block it.

The campaign we discovered is based on two domains (see the IoCs section below), controlled by the attackers, that contain malicious Android files for download. The attackers lure potential victims to these domains via posting or commenting on Reddit (Figure 1) or XDA Developers (Figure 2).

Mostly, the topics of the posts were porn-related; alternatively, we’ve seen also technical topics used as a lure. In all comments or posts, the attackers included links or QR codes pointing to the malicious apps.


Figure 1. The attacker’s Reddit profile with malicious posts and comments




Figure 2. Some of the attackers’ malicious posts on the XDA Developers forum

In one link that was shared on Reddit, the attackers used the URL shortener bit.ly. This bit.ly URL was created on Jun 11, 2019 and as seen in Figure 3 its statistics show that, at the time of writing, it had reached 59 clicks from different sources and countries.


Figure 3. Statistics for the bit.ly link shared on Reddit during the ransomware campaign

As previously mentioned, the Android/Filecoder.C ransomware spreads links to itself via SMS messages to all the entries in the victim’s contact list.

These messages include links to the ransomware; to increase the potential victims’ interest, the link is presented as a link to an app that supposedly uses the potential victim’s photos, as seen in Figure 4.

To maximize its reach, the ransomware has the 42 language versions of the message template seen in Figure 5. Before sending the messages, it chooses the version that fits the victim device’s language setting. To personalize these messages, the malware prepends the contact’s name to them.


Figure 4. An SMS with a link to the ransomware; this language variant is sent if the sending device has the language set to English


Figure 5. A total of 42 language versions that are hardcoded in the ransomware

Once potential victims receive an SMS message with the link to the malicious application, they need to install it manually. After the app is launched, it displays whatever is promised in the posts distributing it – most often, it’s a sex simulator online game. However, its main purposes are C&C communication, spreading malicious messages and implementing the encryption/decryption mechanism.

As for C&C communication, the malware contains hardcoded C&C and Bitcoin addresses in its source code. However, it can also dynamically retrieve them: they can be changed anytime by the attacker, using the free Pastebin service.


Figure 6. An example of a set of addresses for the ransomware to retrieve C&C addresses

The ransomware has the ability to send text messages, due to having access to the user’s contact list. Before it encrypts files, it sends a message to each of the victim’s contacts using the technique described in the “Spreading” section above.

Next, the ransomware goes through files on accessible storage – meaning all the device’s storage except where system files reside – and encrypts most of them (see the “File encryption mechanism” section below). After the files are encrypted, the ransomware displays its ransom note (in English) as seen in Figure 7.


Figure 7. A ransom note displayed by Android/Filecoder.C

It is true that if the victim removes the app, the ransomware will not be able to decrypt the files, as stated in the ransom note. However, the files can still be recovered, due to flawed encryption (see more in the following section). Also, according to our analysis, there is nothing in the ransomware’s code to support the claim that the affected data will be lost after 72 hours.

As seen in Figure 8, the requested ransom is partially dynamic. The first part of what will be the amount of bitcoins to be requested is hardcoded – the value is 0.01 – while the remaining six digits are the user ID generated by the malware.

This unique practice may serve the purpose of identifying the incoming payments. (In Android ransomware, this is typically achieved by generating a separate Bitcoin wallet for each encrypted device.) Based on the recent exchange rate of approximately US$9,400 per bitcoin, the derived ransoms will fall in the range US$94-188 (assuming that the unique ID is generated randomly).


Figure 8. How the malware calculates the ransom

Unlike typical Android ransomware, Android/Filecoder.C doesn’t prevent use of the device by locking the screen.

As seen in Figure 9, at the time of writing, the mentioned Bitcoin address, which can be dynamically changed but was the same in all cases we’ve seen, has recorded no transactions.


Figure 9. The Bitcoin address used by the attackers

The ransomware uses asymmetric and symmetric encryption. First, it generates a public and private key pair. This private key is encrypted using the RSA algorithm with a hardcoded value stored in the code and sent to the attacker’s server. The attacker can decrypt that private key and, after the victim pays the ransom, send that private key to the victim to decrypt their files.

When encrypting files, the ransomware generates a new AES key for each file that will be encrypted. This AES key is then encrypted using the public key and prepended to each encrypted file, resulting in the following pattern: ( (AES)public_key + (File)AES ).seven

The file structure is seen in Figure 10.


Figure 10. Overview of encrypted file structure

The ransomware encrypts the following filetypes, by going through accessible storage directories:

“.doc”, “.docx”, “.xls”, “.xlsx”, “.ppt”, “.pptx”, “.pst”, “.ost”, “.msg”, “.eml”, “.vsd”, “.vsdx”, “.txt”, “.csv”, “.rtf”, “.123”, “.wks”, “.wk1”, “.pdf”, “.dwg”, “.onetoc2”, “.snt”, “.jpeg”, “.jpg”, “.docb”, “.docm”, “.dot”, “.dotm”, “.dotx”, “.xlsm”, “.xlsb”, “.xlw”, “.xlt”, “.xlm”, “.xlc”, “.xltx”, “.xltm”, “.pptm”, “.pot”, “.pps”, “.ppsm”, “.ppsx”, “.ppam”, “.potx”, “.potm”, “.edb”, “.hwp”, “.602”, “.sxi”, “.sti”, “.sldx”, “.sldm”, “.sldm”, “.vdi”, “.vmdk”, “.vmx”, “.gpg”, “.aes”, “.ARC”, “.PAQ”, “.bz2”, “.tbk”, “.bak”, “.tar”, “.tgz”, “.gz”, “.7z”, “.rar”, “.zip”, “.backup”, “.iso”, “.vcd”, “.bmp”, “.png”, “.gif”, “.raw”, “.cgm”, “.tif”, “.tiff”, “.nef”, “.psd”, “.ai”, “.svg”, “.djvu”, “.m4u”, “.m3u”, “.mid”, “.wma”, “.flv”, “.3g2”, “.mkv”, “.3gp”, “.mp4”, “.mov”, “.avi”, “.asf”, “.mpeg”, “.vob”, “.mpg”, “.wmv”, “.fla”, “.swf”, “.wav”, “.mp3”, “.sh”, “.class”, “.jar”, “.java”, “.rb”, “.asp”, “.php”, “.jsp”, “.brd”, “.sch”, “.dch”, “.dip”, “.pl”, “.vb”, “.vbs”, “.ps1”, “.bat”, “.cmd”, “.js”, “.asm”, “.h”, “.pas”, “.cpp”, “.c”, “.cs”, “.suo”, “.sln”, “.ldf”, “.mdf”, “.ibd”, “.myi”, “.myd”, “.frm”, “.odb”, “.dbf”, “.db”, “.mdb”, “.accdb”, “.sql”, “.sqlitedb”, “.sqlite3”, “.asc”, “.lay6”, “.lay”, “.mml”, “.sxm”, “.otg”, “.odg”, “.uop”, “.std”, “.sxd”, “.otp”, “.odp”, “.wb2”, “.slk”, “.dif”, “.stc”, “.sxc”, “.ots”, “.ods”, “.3dm”, “.max”, “.3ds”, “.uot”, “.stw”, “.sxw”, “.ott”, “.odt”, “.pem”, “.p12”, “.csr”, “.crt”, “.key”, “.pfx”, “.der”

However, it doesn’t encrypt files in directories that contain the strings “.cache”, “tmp”, or “temp”.

The ransomware also leaves files unencrypted if the file extension is “.zip” or “.rar” and the file size is over 51,200 KB/50 MB, and “.jpeg”, “.jpg” and “.png” files with a file size less than 150 KB.

The list of filetypes contains some entries unrelated to Android and at the same time lacks some typical Android extensions such as .apk, .dex, .so. Apparently, the list has been copied from the notorious WannaCryptor aka WannaCry ransomware.

Once the files are encrypted, the file extension “.seven” is appended to the original filename, as seen in Figure 11.


Figure 11. Encrypted files with the extension “.seven”

Code to decrypt encrypted files is present in the ransomware. If the victim pays the ransom, the ransomware operator can verify that via the website seen in Figure 12 and send the private key to decrypt the files.


Figure 12. Ransom payment verification web page

However, because of the hardcoded key value that is used to encrypt the private key, it would be possible to decrypt files without paying the ransom by changing the encryption algorithm to a decryption algorithm. All that is needed is the UserID (see Figure 13) provided by the ransomware, and the ransomware’s APK file in case its authors change the hardcoded key value. So far, we have seen the same value in all samples of the Android/Filecoder.C ransomware.


Figure 13. The UserID can be found in the ransom note

First of all, keep your devices up to date, ideally set them to patch and update automatically, so that you stay protected even if you’re not among the most security savvy users.
If possible, stick with Google Play or other reputable app stores. These markets might not be completely free from malicious apps, but you have a fair chance of avoiding them.
Prior to installing any app, check its ratings and reviews. Focus on the negative ones, as they often come from legitimate users, while positive feedback is often crafted by the attackers.
Focus on the permissions requested by the app. If they seem inadequate for the app’s functions, avoid downloading the app.
Use a reputable mobile security solution to protect your device.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

Veteran Suicide Prevention: The Urgency Behind CVN's Push

Updated Category News Views 3

Veteran suicide is a crisis staring us square in the face, with rates 60% higher than the general population. It's a grim reminder that the mental toll on those who've served is a deep chasm hard to bridge. Cohen Veterans Network (CVN) is stepping up to the plate with a new campaign dubbed 'Ask Anyway: Conversations to Save a Life'. This isn't just any awareness...

Continue Reading
Three Lions Acquisition Corp: $100M IPO Hits Nasdaq

Updated Category News Views 2

Three Lions Joins the SPAC Playground The market's buzzing today as Three Lions Acquisition Corp. sauntered in with a $100M debut. Yep, they're the latest Special Purpose Acquisition Company out to net some big fish in the sports, hospitality, and real estate waters. A blank check company raising this kind of dough ain't exactly a novelty, but it never fails to turn a few...

Continue Reading
McLean Launches Program to Foster AI Capability

Updated Category News Views 2

Driving AI Adoption: A Shift Towards Human-Centric Learning McLean & Company has dropped an initiative that’s like laying fresh tracks for AI inclusion in businesses. Dubbed the Human-Centric AI Program, it’s a wake-up call to organizations struggling to shift AI from a novelty to a natural part of operations. This isn’t just about fiddling with AI tools; it’s...

Continue Reading
Kroger's Strategic Shift: Ibbotson's Bold New Charge

Updated Category News Views 3

Kroger Welcomes a Seasoned Retail Veteran Change often arrives with the dawn of new leadership. As Kroger takes a page from the playbook of large-scale retail transformation, they've enlisted Mark Ibbotson. Effective September 14, Ibbotson will step in as Executive Vice President and Chief Store Operations Officer. It's a roll of the dice that could either accelerate...

Continue Reading
Mega Matrix Shares Consolidation Ahead: What It Means

Updated Category News Views 1

Quick and Unexpected Moves at Mega Matrix Just when you thought things couldn't get more complicated in the world of Mega Matrix Inc. (NYSE: MPU), they pull a rabbit out of the hat at their Extraordinary General Meeting on September 1st. Held at their office in Singapore, shareholders green-lighted some heavy-hitting changes like a share consolidation—twenty into one...

Continue Reading
Mito Health Achieves Milestone: A Million Lab Tests

Updated Category News Views 3

A Million Reasons to Take Note: Mito Health Expands If you've been snoozing on this, it's time to wake up. Mito Health just blew past a major milestone, hitting over one million lab tests since they set up shop in the diagnostics marketplace. That's no small potatoes for a company that's still fresh-faced since its 2023 debut in San Francisco. Revolutionizing Preventive...

Continue Reading
Telit Cinterion Secures U.S. Manufacturing with PA Facility

Updated Category News Views 1

Telit Cinterion Takes a Bold Step in U.S. Manufacturing Here's a move you don't see every day: Telit Cinterion, one of the leading players in the IoT scene, is planting its flag firmly in the good ol' U.S. of A. They're ramping up to start churning out 4G and 5G IoT modules right on American soil by October 2026. This isn't just a small-scale ambition, folks. We're...

Continue Reading
Crunch Fitness Organizes Major 9/11 Tribute Event

Updated Category News Views 2

A Climb for Remembrance In the realm of tributes that hit home, Fitness Ventures might have just nailed one. On this 25th anniversary of September 11, they're pulling no punches by bringing the gritty spirit of NYC right into the heart of 106 Crunch Fitness locations across America. You want to talk about a tribute that resonates, this is it—a Nationwide 9/11...

Continue Reading
ITP Media's Bold Move: Ready for Asian Market Surge

Updated Category News Views 0

Pushing Boundaries: ITP Media Group Eyes Asia ITP Media Group isn't here to tiptoe around the media market; they're diving headfirst with the recent takeover of Heart Media Group. A bold move, some might say, in this volatile world of media mergers and acquisitions. But let's break down what this really means. A Strategic Bet on Luxury To start, ITP Media is beefing up...

Continue Reading
Nanochon Tests Innovative Knee Implant in Human Trial

Updated Category News Views 2

Mending Knees with New Tech: The Chondrograft™ Debut Picture this: Nanochon's Chondrograft™ just hit the ground running. They've got a bite out of the future by diving headfirst into their First-in-Human (FIH) clinical study. This ain't your grandma's knee replacement talk. This is about changing the game for those knee cartilages that let out a groan every time you...

Continue Reading

Top 5 Most Recently Viewed Articles

Ginkgo Bioworks Welcomes Brian O'Sullivan to Drive Growth

Updated Category News Views 116

Ginkgo Bioworks Enhances Leadership with New Appointment In a strategic move to accelerate growth, Ginkgo Bioworks has appointed Brian O'Sullivan as the Head of Commercial for Ginkgo Automation. Brian, a seasoned executive in the life sciences sector, steps in at a crucial time for the organization, which is dedicated to pioneering advancements in cell programming and...

Continue Reading
Future Growth of Plastics Market Expected to Reach $984.11B

Updated Category News Views 220

Plastics Market Growth Potential The global plastics market is currently valued at approximately USD 678.98 billion and is on a projected path to reach around USD 984.11 billion by 2034. This growth represents a compound annual growth rate (CAGR) of 4.21% during the forecast period. The driving force behind this expansion is the increasing demand for lightweight and...

Continue Reading
Daxor Corporation Achieves Strong Financial Results and Growth

Updated Category News Views 101

Impressive Financial Growth at Daxor Corporation 2025 is starting off on a high note for Daxor Corporation (Nasdaq: DXR), a pioneer in blood volume measurement technology. The company has recently announced the filing of its Annual Report to Shareholders, revealing key updates on its financial standing and operational success. Significant Revenue Increase and NAV Growth...

Continue Reading
Skanska Expands Infrastructure Projects with Bridge Deck Renovation

Updated Category News Views 150

Skanska's Latest Infrastructure Project: Bridge Deck Replacement Skanska is embarking on a significant infrastructure project by entering a joint venture with California Engineering Contractors to replace the bridge deck of the Vincent Thomas Bridge. The total value of this contract with the California Department of Transportation is substantial, amounting to USD 534...

Continue Reading
Tranter's Role in Advancing Carbon Capture Technology

Updated Category News Views 119

Tranter's Role in Advancing Carbon Capture Technology Tranter has recently secured a significant contract to provide gasketed plate and frame heat exchangers for the innovative Net Zero Teesside Power project, marking a pivotal moment in the evolution of low-carbon energy generation. This project is poised to become a landmark in carbon capture technology, positioning...

Continue Reading