Skip to main content

Boteraser | Website and Server Security Solutions

DoubleLocker

Malware

⚠️ Overview

DoubleLocker is a strain of Android ransomware first discovered in May 2017 by ESET researchers. It is unique because it combines file encryption with device-locking capabilities, categorizing it as both ransomware and a locker. The malware is attributed to an unknown threat actor and primarily spreads through repackaged legitimate applications distributed via third-party app stores and phishing websites.

🔧 Technical Capabilities

DoubleLocker encrypts files on the device’s external storage using AES-256 encryption and appends the '.encrypt' extension to affected files. It simultaneously abuses Android’s Device Administrator API to change the device’s PIN or pattern lock, locking the user out entirely. The malware propagates by repackaging popular apps (e.g., Adobe Flash Player, Google Update) and does not use a traditional command-and-control (C2) infrastructure for encryption; instead, the decryption key is sent to a C2 server operated by the attacker, and the ransom note demands payment in Bitcoin. For persistence, DoubleLocker prevents removal of Device Administrator privileges and disables key system settings such as “Find My Device”. Evasion techniques include obfuscation of the malicious payload and requesting device admin rights immediately after installation under the guise of a legitimate system update.

📜 History & Notable Incidents

DoubleLocker was first reported by ESET in a May 2017 blog post detailing its dual ransomware/locker mechanism. No specific high-profile victims or CVE identifiers have been publicly documented for this malware; however, it was notably covered by BleepingComputer and featured in a 2018 academic paper on Android ransomware analysis (IEEE Access). No law enforcement actions have been confirmed against the operators, and the malware’s activity appears to have declined after 2019 as Android security updates mitigated the Device Admin API abuse.

🔍 Detection Indicators

Known file hashes are not widely published, but researchers have identified the ransom note file named “HOW_TO_UNLOCK.txt” or “READ_ME.txt” containing the attacker’s Bitcoin wallet address and a personal ID. Behavioral indicators include a sudden change of device PIN without user action, the appearance of files with the .encrypt extension, and the application package name often mimicking system tools (e.g., com.android.update). Network indicators include HTTPS communication with C2 domains hosted on bulletproof hosting services; ESET’s report lists sample C2 URLs such as http://doublelocker[.]xyz (no longer active).

☠️ Risk & Impact

DoubleLocker causes irreversible data loss if victims do not pay the ransom, as the AES‑256 encryption key is stored only on the attacker’s server. The device lockout renders the phone completely unusable, preventing access to contacts, photos, and other files. While primarily affecting consumer Android devices, the malware’s distribution method via repackaged apps puts any user who sideloads applications at risk.

🛡️ Mitigation

To defend against DoubleLocker, users should only install apps from the Google Play Store, enable Google Play Protect, and avoid granting Device Administrator privileges to unknown apps. Regular backups to a secure cloud service or external storage are recommended; ESET also advises keeping Android OS security patches up to date and using endpoint protection solutions that detect attempts to abuse the Device Admin API.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.