This devious Android ransomware pretends to be the FBI

(Image credit: Shutterstock.com)

A new form of ransomware is spoofing emails from the FBI in order to trick victims into downloading malware.

Researchers from Check Point have revealed the malware, known as "Black Rose Lucy", is targeting Android devices in order to install threats that force users to pay out to unlock their device.

The ransom note goes a step further than typical messages by pretending to be from the FBI, displaying a browser message that accuses the victim of possessing pornographic content on their device. 

Black Rose Lucy

Check Point says that it first detected Black Rose Lucy in September 2018, with the malware thought to have originated in Russia. It disguises itself as a harmless video player application, tricking the user into giving away administrative access to te device.

The malware's message states that the user’s details have been uploaded to the FBI Cyber Crime Department’s Data Center, accompanied by a list of legal offenses that the user is accused of supposedly committing.

To make the situation “go away” and unencrypt their device, the victim is instructed to pay a $500 “fine”, although in a change to many ransomware scams, the payment needs to be made via credit card, not Bitcoin.

“We are seeing an evolution in mobile ransomware: it’s becoming more sophisticated and efficient," noted Check Point Manager of Mobile Research, Aviran Hazum. 

"Threat actors are learning fast, drawing from their experience of past campaigns, and the impersonation of a message from the FBI is a clear scare tactic. Sooner or later, we anticipate the mobile world will experience a major destructive ransomware attack. It’s a scary but very real possibility, and we urge everyone to think twice before clicking on anything to accept or enable functions while browsing videos on social media."

Check Point recommends that users should install a security solution on their devices and only use official app stores in order to stay safe from such threats, as well as keeping their device’s OS and apps up to date at all times.

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras