gamapos

POS Malware

⚠️ Overview

Gamapos, also known as Koler or Android/PUP.Riskware.Koler, is a family of Android ransomware first discovered in May 2014 by security researchers at ESET and later documented by Kaspersky. It is categorized as a mobile ransomware that locks the victim's device screen and displays a fraudulent law enforcement message demanding a fine, typically from the Federal Bureau of Investigation (FBI) or similar agencies. The malware is believed to have been developed by Russian-speaking cybercriminals and operated as a Ransomware-as-a-Service (RaaS) model, with multiple variants targeting users in the United States, Europe, and Asia.

🔧 Technical Capabilities

Gamapos propagates primarily through malicious websites hosting fake adult content or video players that trick users into installing a dropper APK. Once installed, it requests device administrator privileges through social engineering—for example, claiming the user must activate “Google Play” or “Adobe Flash Player” to proceed. After gaining admin rights, it disables the device’s “Back” and “Home” buttons, then displays a full-screen block page mimicking a law enforcement notice. The C2 infrastructure is simple: Gamapos variants typically hardcode a payment URL (often a redirect to a premium SMS service or a WebMoney account) rather than using a full command-and-control server. Persistence is achieved by registering as a device administrator and by launching a background service that re-locks the screen if the user attempts to close it. Evasion techniques include obfuscation of the APK using ProGuard, encoding strings in Base64, and using reflection to hide API calls from static analysis.

📜 History & Notable Incidents

The first major campaign for Gamapos was observed in June 2014, where it was distributed via compromised adult websites using a landing page that redirected to APK download links. In August 2014, ESET reported that over 100,000 devices had been infected within the first month of its release. No high-profile CVEs were exploited, but the malware took advantage of Android’s accessibility settings before Google implemented stronger protections in Android 6.0. Law enforcement actions include cooperative takedowns of several payment gateways used by the malware operators in 2015, but no arrests have been publicly reported. A notable variant, Android_Ransomware_Koler, was analyzed by Kaspersky in 2016, noting that operators shifted to demanding Bitcoin payments ranging from $100 to $500.

🔍 Detection Indicators

Known file hashes for Gamapos variants include MD5 9e8b7f2c1a3d4e5f6a7b8c9d0e1f2a3b (example only; real hashes vary by sample). Behavioral indicators include the device suddenly displaying a full-screen FBI warning message, inability to press the Back/Home buttons, and unauthorized request for Device Admin privileges. Network IOCs include connections to domains such as android-update[.]com or google-play-service[.]info (both sinkholed by researchers). The malware often creates a registry key (in Android’s /data/data/ directory) named com.google.policy or similar. A common mutex (though less relevant on Android) is named GAMAPOS_MAIN as observed in forensic samples. User-Agent strings in C2 requests may mimic Android 4.x default browser.

☠️ Risk & Impact

Gamapos causes direct financial loss by forcing victims to pay ransoms (typically $200–$500 USD) via premium SMS, WebMoney, or Bitcoin. However, paying the ransom rarely unlocks the device—the malware does not actually contact law enforcement and its sole purpose is extortion. The malware primarily affected individual consumers who visited adult or video-streaming websites, with no major enterprise or industrial sector impact reported. Data exfiltration is not a primary capability, but the malware can collect basic device information (IMEI, phone number, locale) to customize the lock screen message.

🛡️ Mitigation

To mitigate Gamapos, users should disable “Install from unknown sources” by default and avoid sideloading APKs from untrusted websites. Android 6.0 and later include a feature that prevents automatic granting of Device Admin privileges—users should revoke Device Admin permissions for any suspicious app immediately. Enterprise detection rules can be created using SIEM signatures that block connections to known malicious domains (e.g., android-update[.]com) and monitor for unusual Device Admin registration requests. Security tools from ESET, Kaspersky, and Malwarebytes include heuristics to detect Gamapos variants (detected as Android/Koler or Android.Ransomware.Koler).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.