ESET reported that the DoubleLocker Android malware combined two extortion techniques on a single device: it changed the victim’s screen PIN and encrypted files stored on the phone. The ransomware, detected as Android/DoubleLocker.A, was described as the first observed Android threat to abuse accessibility services to gain elevated privileges and then use them to activate device administrator rights, establish persistence, and lock users out while encrypting data with AES. Encrypted files were renamed with the .cryeye extension, and victims were told to pay 0.0130 BTC within 24 hours.
The malware was reportedly spread mainly through compromised websites posing as a fake Adobe Flash Player update. After installation, it set itself as the default Home application, blocked normal recovery steps, and assigned a random PIN that was not stored locally or sent to the operators, preventing straightforward recovery. ESET said the most reliable remediation was a factory reset, while some rooted devices with USB debugging already enabled might be unlocked through ADB; however, encrypted files could not be restored without the attackers’ decryption key.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
ESET researcher Lukáš Štefanko said the company had seen a test version of a similar ransom-banker concept in the wild as early as May 2017. This predates the later DoubleLocker discovery.
ESET reported a new Android ransomware family, detected as Android/DoubleLocker.A, that both changes a victim device’s PIN and encrypts files. The company described it as the first observed Android ransomware to misuse accessibility services and combine device locking with file encryption in this way.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.