Update: According to Reddit user luca020400, the hard-coded password is "4865083501".
The world is paralyzed in the clutches of the COVID-19 pandemic right now, and a number of wrongdoers are trying their best to benefit from the panic and confusion that's running rampant. Aside from speculation and price-gouging with scarce hygiene products, scalpers are trying to take away one of the vital mediums of information spread - your smartphone.
A seemingly-useful Android app that claims to be showing the spread of coronavirus in your general area is reportedly locking users out of their devices and requiring ransom to unlock the phones. The so-called CovidLock ransomware takes advantage of a security flaw and creates a bespoke screen lock password that the user can't guess on their own.
The malicious app claims to show a heatmap with COVID-19 cases around the user and is not found on the Google Play Store. Instead, it was hosted at the coronavirusapp[.]site domain. A kind reminder that downloading unsigned apps from outside the Play Store is not recommended.
The website hosting the malicious app
Newly discovered ransomware performs a screen-lock attack by forcing a change in the password required to unlock a phone, explains DNS threat intelligence company DomainTools today in a blog post authored by Tarik Saleh, senior security engineer and malware researcher. For Android Nougat devices and later versions, the attack only works if the user has never bothered to set a screen lock password in the first place. However, older devices are more vulnerable to the flaw.
CovidLock ransomware
Once a phone gets infected by the coronavirus tracker, the unlucky users are asked for a $100 in bitcoin to be paid within 48 hours in order to remove the custom screen lock. Staying true to their lowly methods, the attackers are also threatening the victims to claim hold of their personal data, like photos, videos, social media accounts, and so on, as well as claiming they have a hold of their GPS location at all times and could remotely wipe the infected Android phone.
“Note: Your GPS is watched and your location is known. If you try anything stupid your phone will be automatically erased,” claims the pathetic ransomware app.
“Cybercriminals like to exploit people when they are at their most vulnerable. They use dramatic events that cause people to be emotional or fearful to drive their profits,” said Saleh. “The coronavirus is no different. Shortly after the first cases were confirmed, DomainTools’ researchers observed a minor uptick in domain names leveraging Coronavirus and COVID-19. These registrations have peaked significantly in the past few weeks and many of them are scams.”
To protect yourself, don't download any shady apps outside of the Play Store and don't buy into the panic!
Create a free account and join our vibrant community
Register to enjoy the full PhoneArena experience. Here’s what you get with your PhoneArena account:
Peter, an experienced tech enthusiast at PhoneArena, is captivated by all things mobile. His impartial reviews and proficiency in Android systems offer readers valuable insights. Off-duty, he delves into the latest cryptocurrency trends and enjoys sci-fi and video games.
Loading Comments...
COMMENT
All comments need to comply with our
Community Guidelines
Phonearena comments rules
A discussion is a place, where people can voice their opinion, no matter if it
is positive, neutral or negative. However, when posting, one must stay true to the topic, and not just share some
random thoughts, which are not directly related to the matter.
Things that are NOT allowed:
Off-topic talk - you must stick to the subject of discussion
Offensive, hate speech - if you want to say something, say it politely
Spam/Advertisements - these posts are deleted
Multiple accounts - one person can have only one account
Impersonations and offensive nicknames - these accounts get banned
Moderation is done by humans. We try to be as objective as possible and moderate with zero bias. If you think a
post should be moderated - please, report it.
Have a question about the rules or why you have been moderated/limited/banned? Please,
contact us.
Things that are NOT allowed: