SLocker is an Android mobile ransomware family and one of the earliest widely documented strains to combine screen-locking behavior with file encryption on mobile devices. It has appeared in multiple forms, including classic lock-screen variants that render the device unusable and more advanced builds that encrypt user files on external storage with AES and demand payment for recovery. Some variants have imitated well-known ransomware branding, including a WannaCry-like interface, while others have masqueraded as topical or benign Android applications such as coronavirus information apps, game cheats, guides, and media players to induce sideload installation.
SLocker primarily targets Android users, especially those installing applications from outside official app stores. Depending on the variant, it may lock the screen, persist across reboot, alter the application icon or wallpaper, and repeatedly prevent normal device access. File-encrypting variants selectively target user data such as downloaded files, images, and videos while avoiding some system-related paths and applying size or filename constraints. Ransom demands have been delivered through localized payment instructions and social-engineering pressure such as countdowns, threats of increased payment, or claims that files will be deleted.
The family has shown substantial variation over time. Researchers have documented weak cryptographic or unlock-key logic in some samples, while later variants modified decryption routines or used packing to hinder static analysis. SLocker has also been observed in supply-chain compromise cases in which infected Android devices were delivered with malware already present, including instances with elevated privileges that made removal difficult without reflashing. Geographic reporting has included campaigns and related samples affecting users in China, Central Asia, Eastern Europe, parts of India, and North Africa. SLocker is generally tracked as mobile ransomware, though some individual samples function only as screen lockers without encrypting data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the file has been encrypted, a suffix will be added to the file name. | Early last month, a new variant of mobile ransomware SLocker (detected by Trend Micro as ANDROIDOS_SLOCKER.OPST) was detected, copying the GUI of the now-infamous WannaCry.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Basic Android locker ransomware disguised as a coronavirus information app that blocks user activity and demands payment.
An Android screen-locking malware family adapted to COVID-19 lures. In this sample, a fake 'About Coronavirus' app locks the device screen, displays an Uzbek ransom message, and demands payment for an unlock code. It persists across reboot and may require ADB, Safe Mode, or the correct code followed by app removal to recover the device.
Android mobile ransomware that disguises itself as game guides, cheating tools, and video players, changes its icon and wallpaper after execution, encrypts files on external storage using AES, appends a suffix to encrypted filenames, and demands payment via QQ. The analyzed variant mimics WannaCry’s interface and uses a simple decrypt-key formula derived from a stored random number.
Mobile ransomware found among the pre-installed malware samples. It encrypts files on the Android device with AES, demands ransom for decryption, and uses Tor for C&C communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.