A coronavirus-tracking app locked users' phones and demanded $100
Full article544 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The app is the latest reminder that trusting Apple and Google to serve as gatekeepers is an effective way to mostly avoid malware.
You can always count on hackers to exploit a terrible situation to try to make a buck.
A new Android app that promises to deliver up-to-date figures on the coronavirus pandemic includes a strain of malicious software that locks up a user’s phone and demands an extortion fee. The ransomware app, called CovidLock, threatens to erase everything on an infected phone if victims don’t pay $100 in bitcoin within 48 hours, according to the security firm DomainTools.
The number of users affected remains unclear. The app is not available in the Google Play store, and was accessible on a standalone website.
DomainTools has said it intends to release a decryption tool for affected victims, while Reddit users claim to already have deciphered the password to release locked data.
The program only represents scammers’ latest attempt to use concerns around the COVID-19 virus to defraud anxious technology users.
Scams, misinformation campaigns, attempted hacks and government surveillance operations have followed the respiratory virus’ spread through the globe. No fewer than four cybersecurity companies detected hacking efforts last week, including spearphishing campaigns that impersonated public health officials from the U.S. and beyond. In one example, hackers cloaked malicious software behind their own version of a global map first published by Johns Hopkins University meant to track COVID-19’s spread.
Operators behind CovidLock played on the same concern and curiosity by claiming they would track the location of victims’ phones, then delete their photos, social media accounts and pictures if no bitcoin payment came through.
The app is the latest proof that trusting Google’s Play store and the App Store as gatekeepers is one way to mitigate the risk of inadvertently downloading malware. While scammers have proven capable of slipping through security controls in both markets, Google and Apple have checks in place meant to stifle this kind of behavior, and then delete nefarious programs that do surface.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/coronavirus-app-locked-phones/