DroidLock
- Malware type
- ransomware, rat, credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:05:54
Context
According to Zimperium, DroidLock has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials, leading to a total takeover of the compromised device. It employs deceptive system update screens to trick victims and can stream and remotely control devices via VNC. The malware also exploits device administrator privileges to lock or erase data, capture the victim's image with the front camera, and silence the device. Overall, it utilizes 15 distinct commands to interact with its C2 panel.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Droidlock (report)
- zimperium.com — Total Takeover Droidlock Hijacks Your Device (report)