AndroidOS/MalLocker.B is Android malware known for masquerading as popular applications, cracked games, and video players to entice installation. It has been observed registering for numerous Android broadcast intents to automatically trigger its payload in response to device and user events. This use of broadcast receivers supports event-driven execution and persistence by allowing the malware to react to operating system activity without requiring continuous foreground interaction. The malware targets Android devices and relies on standard platform mechanisms for background activation, which can make malicious behavior harder for end users to distinguish from legitimate application activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android ransomware/malware variant that registers numerous broadcast intents to automatically trigger its payloads.
Android locker malware that disguises itself as popular apps, pirated games, and media players.
Android ransomware/malware variant that uses numerous broadcast intents to automatically trigger payload execution.
... AndroidOS/MalLocker.B ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.