CovidLock is an Android ransomware family that emerged in early 2020 and exploited public fear surrounding the COVID-19 pandemic by masquerading as a coronavirus tracking or outbreak-map application. It was distributed outside the official Google Play ecosystem as a sideloaded APK delivered from attacker-controlled websites and relied on social engineering to persuade users to install it and grant elevated permissions.
After installation, CovidLock requested device administrator access and, in some reported cases, Accessibility-related permissions under the pretense of enabling pandemic alerts or nearby-infection notifications. Once activated, it locked the victim’s device, changed the device password, and displayed a ransom note demanding payment in cryptocurrency within a short deadline while threatening data loss or public exposure of personal information. Reporting consistently associates the malware with device-locking extortion behavior against Android users.
Public reporting on whether CovidLock performed real file encryption is inconsistent. Some accounts described it as encrypting files on the device, while reverse-engineering of a widely analyzed sample found that it primarily functioned as locker ransomware and did not actually encrypt files or exfiltrate data. High-confidence characterization therefore supports Android locker-style ransomware behavior centered on denying access to the device through abuse of administrative controls rather than confirmed large-scale data theft.
CovidLock is notable as an early example of pandemic-themed mobile ransomware and illustrates how threat actors rapidly weaponized crisis-related lures to obtain initial access on consumer devices. Its targeting was opportunistic rather than sector-specific, focusing on Android users seeking COVID-19 information or tracking tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Once opened, the app asks for access to your lock screen... The app also asks for permission of an Android phone's accessibility settings... If an unsuspecting user grants these permissions to the app, ransomware dubbed "CovidLock" is enabled.
After the initial phase, the app requests access to the Android's Accessibility feature... attackers often exploit this functionality to keep their malware persistent.
"You have 48 hours to pay 100$ [sic] in bitcoin or everything will be erased... your contacts, your pictures and videos... the phone memory will be completely erased"
When downloaded, this app encrypts the files on the user’s device... demanding a ransom of cryptocurrency to regain access.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android ransomware delivered through fake COVID tracking apps; abuses permissions to gain device control and displays a lock-screen ransom note.
Android ransomware masquerading as a coronavirus tracking app. It requests battery optimization exclusion, accessibility access, and administrator privileges, then locks the device and displays a ransom demand for $250 in bitcoin. The sample analyzed did not actually encrypt files or exfiltrate data; instead, it used a hard-coded unlock key and hid its icon/process to impede removal.
Android ransomware disguised as a COVID-19 tracking app that locks victims out of their device, encrypts files, changes the device password, and demands cryptocurrency payment for access restoration.
Android ransomware disguised as a coronavirus outbreak tracking app. It abuses lock screen and accessibility permissions to lock the device and demand a $100 Bitcoin payment within 48 hours, threatening data erasure and public leakage of social media accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.