Skip to content
Android warning issued as fake apps spread DroidLock ransomware demanding payment

Android warning issued as fake apps spread DroidLock ransomware demanding payment

Themirror • December 11, 2025

Android users are being urged to remain alert following the discovery of a dangerous new cyberattack.

This latest security threat is particularly alarming, as infected devices become completely locked, with victims instructed to pay a ransom or risk permanent deletion of their data . The malicious software, named DroidLock, was identified by Zimperium's security team and is currently targeting Android users across several European regions.

The malware spreads through harmful websites that promote counterfeit applications disguised as legitimate software. Upon installation, DroidLock gains full access to devices and monitors the passcodes users enter to unlock their screens. After obtaining this information, cybercriminals can modify the passcode and prevent the legitimate owner from accessing their device.

Some victims have received a screen overlay demanding ransom payment, threatening deletion of all files.

A countdown clock displays the remaining time to meet the demands, reports the Mirror .

"The ZLabs research team has identified a new threat campaign targeting Android users," Zimperium explained.

"DroidLock, a malware more accurately classified as ransomware, propagates via phishing websites.

"It has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials, leading to a total takeover of the compromised device.

"It employs deceptive system update screens to trick victims and can stream and remotely control devices via VNC.

"The malware also exploits device administrator privileges to lock or erase data, capture the victim's image with the front camera, and silence the device."

While DroidLock hasn't yet arrived in the UK, Android users shouldn't become complacent.

To protect themselves, it's essential that all Android users exclusively download applications from official sources like Google's Play Store.

If prompted to install software directly from websites, users should thoroughly verify the developer's credentials and avoid downloading anything that appears suspicious.

Remain vigilant and exercise caution before installing any applications on your Android device.

Extracted Entities

Attack Types (3)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)

Tools (1)