Skip to content

Slocker

SLocker is a long-established Android ransomware family encompassing both screen-locking and file-encrypting variants.

Slocker

Family profile

SLocker is a long-established Android ransomware family encompassing both screen-locking and file-encrypting variants. Screen lockers prevent normal device access and demand payment for an unlock code, while encrypting variants use AES to encrypt user files and demand payment for decryption. Some variants use Tor for command-and-control communications.

SLocker commonly masquerades as legitimate applications, including game cheats, game guides, video players, and coronavirus information tools, encouraging users to sideload malicious apps. It has also been discovered pre-installed on Android devices through supply-chain compromise affecting devices used by telecommunications and technology companies. A WannaCry-inspired variant copied that ransomware’s interface, changed application branding and device wallpaper, and encrypted selected user files on external storage. Later variants modified their decryption logic and sometimes used packing to hinder static detection.

A coronavirus-themed screen-locking variant displayed Uzbek-language payment demands, survived reboots, and obstructed normal application removal without encrypting user data. Android 8.0 and later restricted some of its button-locking behavior. Certain analyzed variants contained weaknesses, including hardcoded unlock codes or predictable decryption-code calculations, that allowed recovery without payment. Threats to delete data or permanently disable devices were not necessarily implemented.

Capabilities

  • Defense Evasion
  • Extortion
  • Persistence

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

MITRE ATT&CK

Slocker in ATT&CK

9 distinct techniques