DroidLock is an Android malware family that functions primarily as mobile ransomware while also providing extensive remote-access and surveillance capabilities. It has been observed targeting Spanish-speaking users through phishing websites that impersonate legitimate brands or services and deliver a dropper application, which then installs the main payload. The malware abuses Accessibility Services and Device Administrator privileges to gain broad control over the device and to self-approve additional permissions.
Once active, DroidLock can lock the device screen with a ransom-style overlay, change lock credentials such as the PIN, block user interaction, mute the device, uninstall applications, and trigger device wipe or factory-reset actions. Unlike file-encrypting ransomware, it is notable for extorting victims primarily through device lockout and threats of destructive data loss rather than cryptographic encryption. The ransom messaging threatens permanent deletion of data if payment is not made within a short deadline.
DroidLock also supports full remote control of compromised devices through VNC-based functionality and maintains command-and-control communications over HTTP and WebSocket channels. Reported command support includes screen streaming, camera activation, notification manipulation, and other device-management actions that enable operators to take over the handset in real time. The malware uses deceptive overlays, including fake system-update screens and credential-harvesting interfaces, to steal unlock patterns, application credentials, and one-time authentication codes. Additional observed collection capabilities include access to SMS messages, call logs, contacts, audio, screen activity, clipboard data, keystrokes, location, and installed application information.
The combination of ransomware-style coercion, credential theft, surveillance, and remote administration makes DroidLock a significant threat to both personal and enterprise-managed Android devices. Compromised phones can become hostile endpoints capable of exposing corporate communications, authentication flows, and sensitive user data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DroidLock is ransomware that targets Android devices, locking users out and demanding a ransom for access.
Android screen-locking malware presented as ransomware; denies access by locking the screen rather than encrypting files.
Android malware that locks devices with a ransomware-like overlay (without encrypting files), steals app-lock credentials, abuses accessibility services and device admin privileges to change lock PIN/password, can lock/erase data, capture images via front camera, silence device, and supports remote control/streaming via VNC.
DroidLock is a sophisticated Android malware that hijacks devices, locks users out, and turns phones into surveillance tools. It uses phishing sites to trick users into installation, abuses Device Administrator permissions, and can remotely control the device, steal credentials via overlays, stream the screen, and capture images from the front camera. While it mimics ransomware by locking users out and demanding contact, it does not encrypt files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.