DoubleLocker is a strain of Android ransomware first discovered in May 2017 by ESET researchers. It is unique because it combines file encryption with device-locking capabilities, categorizing it as both ransomware and a locker. The malware is attributed to an unknown threat actor and primarily spreads through repackaged legitimate applications distributed via third-party app stores and phishing websites.
DoubleLocker encrypts files on the device’s external storage using AES-256 encryption and appends the '.encrypt' extension to affected files. It simultaneously abuses Android’s Device Administrator API to change the device’s PIN or pattern lock, locking the user out entirely. The malware propagates by repackaging popular apps (e.g., Adobe Flash Player, Google Update) and does not use a traditional command-and-control (C2) infrastructure for encryption; instead, the decryption key is sent to a C2 server operated by the attacker, and the ransom note demands payment in Bitcoin. For persistence, DoubleLocker prevents removal of Device Administrator privileges and disables key system settings such as “Find My Device”. Evasion techniques include obfuscation of the malicious payload and requesting device admin rights immediately after installation under the guise of a legitimate system update.
DoubleLocker was first reported by ESET in a May 2017 blog post detailing its dual ransomware/locker mechanism. No specific high-profile victims or CVE identifiers have been publicly documented for this malware; however, it was notably covered by BleepingComputer and featured in a 2018 academic paper on Android ransomware analysis (IEEE Access). No law enforcement actions have been confirmed against the operators, and the malware’s activity appears to have declined after 2019 as Android security updates mitigated the Device Admin API abuse.
Known file hashes are not widely published, but researchers have identified the ransom note file named “HOW_TO_UNLOCK.txt” or “READ_ME.txt” containing the attacker’s Bitcoin wallet address and a personal ID. Behavioral indicators include a sudden change of device PIN without user action, the appearance of files with the .encrypt extension, and the application package name often mimicking system tools (e.g., com.android.update). Network indicators include HTTPS communication with C2 domains hosted on bulletproof hosting services; ESET’s report lists sample C2 URLs such as http://doublelocker[.]xyz (no longer active).
DoubleLocker causes irreversible data loss if victims do not pay the ransom, as the AES‑256 encryption key is stored only on the attacker’s server. The device lockout renders the phone completely unusable, preventing access to contacts, photos, and other files. While primarily affecting consumer Android devices, the malware’s distribution method via repackaged apps puts any user who sideloads applications at risk.
To defend against DoubleLocker, users should only install apps from the Google Play Store, enable Google Play Protect, and avoid granting Device Administrator privileges to unknown apps. Regular backups to a secure cloud service or external storage are recommended; ESET also advises keeping Android OS security patches up to date and using endpoint protection solutions that detect attempts to abuse the Device Admin API.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.