Story image

Here are the top trends in Android ransomware right now

14 Mar 2017

2016 brought some interesting developments to the Android ransomware scene, seeing ransomware emerge as one of the most pressing cybersecurity issues on the mobile platform. Authors of lock-screen ransomware, as well as file-encrypting “crypto-ransomware”, used copycat techniques proven effective in desktop malware, as well as develop their own sophisticated methods specifically designed for Android users.

With more and more consumers switching from PC to mobile, the devices are used to store increasing amounts of valuable data, making Android ransomware ever more worthwhile for attackers. According to ESET LiveGrid, the number of Android ransomware detections has grown in year on year comparisons by more than 50%, with the largest spike in the first half of 2016.

Figure 1: Android ransomware detection trend, according to ESET LiveGrid

Among the most dominant tactics used by cybercriminals, lock-screen “police ransomware” has continued to prove its place as the go-to means of scaring victims into paying up. Apart from observing gradual improvements in features of Android ransomware, ESET researchers have also seen cybercriminals put increased effort into keeping a low profile by encrypting and burying the malicious payload deeper into the infected apps.

Target-wise, Android ransomware operators have been shifting their focus from Eastern European to US mobile users. However, last year also demonstrated an increased activity on the Asian market. This could be seen in the Jisut lock-screen with its localized Chinese ransom message and doubled detections in the previous 12 months.

Article by Ondrej Kubovič, security evangelist, ESET.

New threat rears its head in new malware report
Check Point’s researchers view Speakup as a significant threat, as it can be used to download and spread any malware.
Oracle updates enterprise blockchain platform
Oracle’s enterprise blockchain has been updated to include more capabilities to enhance development, integration, and deployment of customers’ new blockchain applications.
Used device market held back by lack of data security regulations
Mobile device users are sceptical about trading in their old device because they are concerned that data on those devices may be accessed or compromised after they hand it over.
Gartner names ExtraHop leader in network performance monitoring
ExtraHop provides enterprise cyber analytics that deliver security and performance from the inside out.
Symantec acquires zero trust innovator Luminate Security
Luminate’s Secure Access Cloud is supposedly natively constructed for a cloud-oriented, perimeter-less world.
Palo Alto releases new, feature-rich firewall
Palo Alto is calling it the ‘fastest-ever next-generation firewall’ with integrated cloud-based DNS Security service to stop attacks.
The right to be forgotten online could soon be forgotten
Despite bolstering free speech and access to information, the internet can be a double-edged sword, because that access to information goes both ways.
Opinion: 4 Ransomware trends to watch in 2019
Recorded Future's Allan Liska looks at the past big ransomware attacks thus far to predict what's coming this year.