A new Android malware strain known as DroidLock has been identified by Zimperium researchers, targeting users—primarily in Spanish-speaking regions—through phishing websites and malicious apps that impersonate legitimate services. Once installed, DroidLock requests device administrator and accessibility permissions, enabling it to lock users out of their devices, change PINs or passwords, wipe data, and even erase the device entirely. The malware employs sophisticated overlay techniques to steal unlock patterns and app credentials, and can stream screen activity, access text messages, call logs, contacts, and audio recordings. Attackers can remotely control infected devices via VNC, turning smartphones into surveillance tools and hostile endpoints.
DroidLock communicates with its command-and-control server using both HTTP and WebSocket protocols, supporting at least 15 different commands for real-time manipulation. The infection process typically involves a dropper app that tricks users into installing the actual payload, bypassing Android security restrictions. Victims are presented with a full-screen ransom overlay, pressuring them to contact the attackers and pay a ransom within 24 hours or risk permanent data destruction. While DroidLock does not encrypt files like traditional ransomware, it achieves similar extortion by threatening to destroy or deny access to user data, making it a significant threat to both personal and corporate Android devices.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
After Zimperium shared its findings with Google, Play Protect was updated to detect and block DroidLock on protected Android devices. This marked the first documented defensive response from a platform vendor to the campaign.
Zimperium's zLabs identified a new Android malware campaign dubbed DroidLock targeting Spanish-speaking users through phishing websites and fake apps. The malware uses a dropper and abuses Accessibility and Device Admin permissions to lock devices, steal credentials, and threaten data destruction for ransom without encrypting files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecybersecuritynews.com
Open sourcemalwarebytes.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcezimperium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.