- Jul 22, 2014
- 2,525
Security researchers have spotted a new Android banking trojan named LokiBot that turns into ransomware and locks users' phones when they try to remove its admin privileges.
The malware is more banking trojan than ransomware — according to SfyLabs researchers, the ones who discovered it — and is used for this purpose primarily.
Just like similar Android banking trojans, LokiBot works by showing fake login screens on top of popular apps. LokiBot targets mobile banking apps by design, but also popular non-banking apps such as Skype, Outlook, and WhatsApp.
LokiBot sold online for $2,000
Similar to Svpeng, CryEye, DoubleLocker, ExoBot, and other recent Android malware families, LokiBot is also sold online on hacking forums. The price for a full LokiBot license is $2,000, paid in Bitcoin.
LokiBot has its own unique features compared to other Android banking trojans. For starters, it can open a mobile browser and load an URL and will install a SOCKS5 proxy to redirect outgoing traffic.
.....
The malware is more banking trojan than ransomware — according to SfyLabs researchers, the ones who discovered it — and is used for this purpose primarily.
Just like similar Android banking trojans, LokiBot works by showing fake login screens on top of popular apps. LokiBot targets mobile banking apps by design, but also popular non-banking apps such as Skype, Outlook, and WhatsApp.
LokiBot sold online for $2,000
Similar to Svpeng, CryEye, DoubleLocker, ExoBot, and other recent Android malware families, LokiBot is also sold online on hacking forums. The price for a full LokiBot license is $2,000, paid in Bitcoin.
LokiBot has its own unique features compared to other Android banking trojans. For starters, it can open a mobile browser and load an URL and will install a SOCKS5 proxy to redirect outgoing traffic.
.....