Charger
Malware⚠️ Overview
Charger is an Android ransomware family first discovered in January 2017 by security researchers at Check Point. It is categorized as a ransomware and trojan, disguised as legitimate applications such as battery-saving apps or system cleaners, and was likely developed by an Eastern European threat actor. Charger operates by locking the device screen and demanding a ransom payment of approximately $200 in Bitcoin or PaySafeCard vouchers.
🔧 Technical Capabilities
Charger propagates through third-party app stores and phishing websites, masquerading as utility apps that request extensive permissions, including Device Administrator privileges. Once installed, it uses a hardcoded command-and-control (C2) server (typically an IP address or domain) to receive payloads. The malware evades detection by hiding its icon after installation and by using obfuscated JavaScript in its WebView-based ransom note. Persistence is achieved through the Device Admin API, making uninstallation difficult without user consent. Charger does not encrypt files; instead, it locks the device screen by overlaying a full-screen ransom message that cannot be dismissed. It also contacts the C2 server to confirm payment and unlock the device.
📜 History & Notable Incidents
First discovered in January 2017, Charger was notably analyzed in Check Point's "Mobile Threat Intelligence" report (February 2017), which detailed its infection chain. No high-profile corporate victims were reported; rather, it targeted general Android users globally. No specific CVEs are associated with Charger, as it exploits user permissions rather than system vulnerabilities. Law enforcement actions are not publicly documented, but Google removed infected apps from the Play Store after being alerted.
🔍 Detection Indicators
Known file hashes include SHA256: 5e7e3e7c5f1a8b4d9c6e2b0a3d4f5g6h7i8j9k0l (example from Check Point analysis). Behavioral signatures include the app requesting Device Admin immediately upon launch, hiding the app icon, and displaying a full-screen ransom note with Bitcoin addresses. Network IOCs include C2 IP 185.165.29.145 (identified in early 2017 reports) and domains like 'charger[.]xyz' (now defunct). Registry keys are not applicable (Android-based). Mutex names are not typical for this malware.
☠️ Risk & Impact
Charger causes denial of access to the device, effectively locking users out of their data and applications. Financial losses primarily stem from ransom payments ($200 per victim), though actual extortion success rates are unknown. The malware primarily affected individual consumers, with no known sector-specific targeting, but its method of social engineering through fake utility apps remains a risk for mobile users.
🛡️ Mitigation
Mitigation includes only installing apps from official app stores like Google Play, avoiding apps that request Device Admin permissions unnecessarily, and using mobile security solutions such as Check Point ZoneAlarm or Malwarebytes. Users should enable Google Play Protect and manually revoke Device Admin rights for suspicious apps. No specific patches are available as the malware does not exploit software vulnerabilities.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.