Skip to main content

New Android ransomware is spreading through text messages

There’s a new type of Android ransomware making the rounds that leverages SMS text messages to spread, according to a new report from cybersecurity company ESET. The ransomware has been active since July 12, and essentially uses victims’ contacts lists to spread.

According to the ESET blog post, the malware is called Android/Filecoder.C, and was first distributed on Android developer forums on Reddit, including the XDA Developers subreddit. On these forums, the malware was distributed through pornographic posts.

Usually, the ransomware is disguised as an online sex simulator game, but sometimes its also a tech-related app. Once downloaded, the infected .APK file initiates contact with a server to access a list of addresses and encrypt and decrypt files in the background. It then sends the text messages, and scans the device to encrypt files with the extension “.seven.” That prevents users from being able to access files on their own device. Users are then told that to decrypt their files, they have to pay a ransom — which is usually between $94 and $188 — in the form of Bitcoin. According to the report, the ransom message could be shown in one of 42 languages, maximizing its reach. The malware is able to choose the language of the system, so the user can understand it. Once the ransom is paid, a the private key is sent to the victim, and they can then decrypt the files.

Once the malware is on a device, it’s able to send text messages to contacts on the phone with a link to an app that apparently uses the recipients’ photos — when, of course, it’s actually a malicious app. Sometimes, the link is masked using a bit.ly link.

It’s important to note that if you do find yourself with the malware, your files may not be lost, and you may not have to pay the ransom. According to ESET, while the ransom message says that files will be deleted in 72 hours, that isn’t always the case. Not only that, but encrypted files can be recovered without paying the attackers — though ESET is quick to note that if the attackers fix the flaws, the malware could become more advanced and become a more serious threat.

So how can you prevent being attacked? Simple — don’t download any apps from third-party sources, and don’t click on links sent via text message that tell you your photos are being used in an app.

Editors' Recommendations

Christian de Looper
Christian’s interest in technology began as a child in Australia, when he stumbled upon a computer at a garage sale that he…
Android phones are about to get a major iMessage feature
Google Messages app on a Pixel 8 Pro, showing an RCS Chat message thread.

Being able to edit sent messages is a popular feature on messaging apps like iMessage and WhatsApp. However, it has yet to arrive to the masses via the Google Messages app on Android phones. Thankfully, that could change very soon.

On X (formerly Twitter), Jhow_kira has shared two screenshots demonstrating how the Google Messages editing feature will work in an upcoming software version. Some Android users, including the X poster, are currently testing this new feature.

Read more
Motorola just launched a new Android phone to take on the Google Pixel 8a
A render of the front and back of the Moto G Stylus 5G (2024).

If you have your heart set on a phone with a stylus, you’re probably familiar with Samsung devices like the Galaxy S24 Ultra and the previous Galaxy S23 Ultra. But there is another company out there that ships phones with a stylus — Motorola. Unlike Samsung’s flagship, the new Moto G Stylus 5G (2024) won’t break the bank thanks to its $400 starting price in the U.S.

The Moto G Stylus 5G (2024) is the latest in a series of midrange stylus-equipped phones that Motorola started releasing in 2020. The latest model keeps up with its predecessors with solid midrange capabilities and, as the name indicates, support for 5G.

Read more
The Google Pixel 8a is official. Here’s everything that’s new
Someone taking a phone call on the aloe Google Pixel 8a.

A week ahead of its annual developers' conference, Google has dropped a new budget phone in its Pixel-A series. The Google Pixel 8a retains the line’s signature look with a horizontal camera island at the back, but serves it in a package that embraces rounded corners and also happens to be fractionally smaller and lighter

The most meaningful changes are reserved for the display, silicon, and battery. The OLED screen’s size remains the same at 6.1 inches with a resolution of 1080 x 2400 pixels. However, the refresh rate has been increased to 120Hz, up from the Google Pixel 7a's 90Hz display. This HDR-ready panel offers a peak brightness of up to 2,000 nits and also features a fingerprint sensor underneath.

Read more