SecurityInformed.com
  • Products
    Video Surveillance
    • Surveillance cameras
    • Video Surveillance software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network Video Recorders (NVRs)
    • IP Dome cameras
    • Security camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Intercom Systems
    • Electronic lock systems
    • Access control cards/ tags/ fobs
    • Access control accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder alarm warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    One System, One Card
    One System, One Card
    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    Hikvision AOV 4G Solar Camera Series for Off-Grid Video Security

    KentixONE – IoT Access And Monitoring For Data Centers

    KentixONE – IoT Access And Monitoring For Data Centers

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Climax Technology HSGW-Gen3 Modular Smart Security Gateway

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

    Delta Scientific DSC50 ‘S’ Barrier: Portable, Crash-Rated Vehicle Mitigation Solution

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    One System, One Card
    One System, One Card
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Alcatraz Completes SOC 2 Audit With A-LIGN
    • Datalogic Showcases AI-Driven Retail Solutions At NRF 2026
    • Deep Sentinel's Solar-Powered Security Solution
    • Eplan And CADENAS Partner For Device Data Expansion
    One System, One Card
    One System, One Card
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • Why Open Matters In The Age Of AI
    • What Are Emerging Applications For Physical Security In Transportation?
    • What Is the Most Overlooked Factor When Installing Security Systems?
    • Amid Rising Certificate Demands, Stricter Compliance And Quantum Threats, PKIaaS Is A Necessity
    One System, One Card
    One System, One Card
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    One System, One Card
    One System, One Card
    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

    Alamo Colleges Boosts Safety With Alcatel-Lucent OmniSwitch Platform

    HID Mobile Access Enhances University Of Dundee Campus

    HID Mobile Access Enhances University Of Dundee Campus

    ASSA ABLOY Aperio Wireless Locks At The Camp: Secure & Sustainable

    ASSA ABLOY Aperio Wireless Locks At The Camp: Secure & Sustainable

    SBB Secures Perimeters With Hanwha Vision Cameras

    SBB Secures Perimeters With Hanwha Vision Cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    One System, One Card
    One System, One Card
    Intersec Dubai 2026

    Intersec Dubai 2026

    DIMDEX 2026

    DIMDEX 2026

    DISTRIBUTECH International 2026

    DISTRIBUTECH International 2026

    Munich Security Conference (MSC) 2026

    Munich Security Conference (MSC) 2026

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Software House
    Other Resources
    • eMagazines
    • Videos
    One System, One Card

    One System, One Card

    Aligning Physical And Cyber Defence For Total Protection

    Aligning Physical And Cyber Defence For Total Protection

    Understanding AI-Powered Video Analytics

    Understanding AI-Powered Video Analytics

    Modernizing Access Control

    Modernizing Access Control

About us Advertise
  • Wire-Free Locks
  • AI special report
  • Cybersecurity special report
  • Casino security & surveillance
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check Out Our Special Report On Cybersecurity

Read now!

Zimperium Uncovers DroidLock Android Malware

11 Dec 2025

Zimperium Uncovers DroidLock Android Malware
Contact company
Contact Zimperium
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Zimperium discovers DroidLock malware, targeting Android users with ransomware-style device takeover tactics.
  • DroidLock exploits phishing websites to bypass Android safeguards, stealing credentials and altering settings.
  • Attackers use WebSocket channels, enabling device wiping, screen streaming, and remote control commands.
Related Links
  • Zimperium: Mobile Security Risks From Rooting Tools
  • Zimperium Highlights Threats From NFC Relay Malware
  • Combat Mobile Bots: Zimperium's Security Solutions
  • ZLabs Unveils Fantasy Hub Spyware-as-a-Service

Zimperium has reported new findings from its zLabs team that reveal DroidLock, an evolving Android malware impacting users in Spain.

Deviating from typical mobile malware, DroidLock functions akin to ransomware, allowing for complete control over devices through methods like screen-locking overlays, credential theft, and remote control operations.

Android Safeguards

Upon installation, the malware automatically gains extra permissions, enabling access to SMS, call logs

Researchers from zLabs discovered that DroidLock disseminates through phishing sites, initiating with a deceptive dropper app designed to circumvent Android's protections and misuse Accessibility Services.

Upon installation, the malware automatically gains additional permissions, enabling access to SMS, call logs, contacts, audio, and more without the user's knowledge.

HTTP and WebSocket Channels

Once established, DroidLock maintains communication with its command-and-control server via HTTP and WebSocket channels. Through these channels, attackers have the capability to execute any of 15 unique commands, such as:

  • Locking the device or altering the PIN/password
  • Resetting the device to factory settings
  • Capturing images through the front camera without detection
  • Muting notifications and limiting user interaction
  • Streaming and remotely controlling the device screen using VNC
  • Deploying full-screen overlays requesting ransom within 24 hours

Dual Overlay Mechanisms

DroidLock retains the ability to wipe the device completely, resulting in a permanent lockout

A significant method involves dual overlay techniques used for stealing lock patterns and app credentials. DroidLock utilizes quick in-memory overlays to record screen unlock patterns, while WebView-based overlays allow attackers to render HTML that harvests credentials from targeted apps.

Additionally, the malware displays a simulated Android system update screen to prevent the victim from shutting down or interrupting the attack process.

Though the ransomware overlay does not encrypt files, DroidLock retains the ability to wipe the device completely, resulting in a permanent lockout for users and ongoing control by the attacker.

Intercept One-Time Passcodes

Vishnu Pratapagiri, a Security Researcher at Zimperium and the author of the report, stated, "For enterprises, a compromised device becomes a hostile endpoint. DroidLock can intercept one-time passcodes, change device credentials, wipe data, and remotely control the user interface."

"Organizations need mobile security that stops these attacks before they disrupt operations or enable account takeover."

Understand how converged physical and cybersecurity systems can scale protection.

Show full press release

Zimperium, the pioneer in mobile security, today announced new research from its zLabs team uncovering DroidLock, a rapidly evolving Android malware campaign targeting users in Spain.

Unlike traditional mobile malware, DroidLock behaves more like full-scale ransomware, enabling complete device takeover through screen-locking overlays, credential theft, and remote control capabilities.

Android safeguards

zLabs researchers found that DroidLock is distributed through phishing websites and begins with a deceptive dropper app designed to bypass Android safeguards and exploit Accessibility Services.

Once installed, the malware automatically approves additional permissions, granting access to SMS, call logs, contacts, audio, and more, without the victim’s awareness.

HTTP and WebSocket channels

After establishing persistence, DroidLock communicates with its command-and-control server using both HTTP and WebSocket channels. Through these channels, attackers can issue any of 15 distinct commands, enabling them to:

  • Lock the device or change the PIN/password
  • Wipe the device through a factory reset
  • Silently capture the victim’s image using the front camera
  • Mute notifications and restrict user interaction
  • Stream the device’s screen and remotely control it via VNC
  • Display ransomware-style full-screen overlays demanding payment within 24 hours

Dual overlay mechanisms

A notable tactic includes dual overlay mechanisms used to steal lock-patterns and app credentials. DroidLock deploys fast in-memory overlays to capture screen unlock patterns, while WebView-based overlays render attacker-controlled HTML to harvest credentials from targeted apps. The malware also displays a convincing fake Android system-update screen to keep victims from powering off or interrupting the attack.

Although the ransomware overlay does not encrypt files, DroidLock can wipe the device entirely, permanently locking users out and enabling indefinite control by the attacker.

Intercept one-time passcodes

“For enterprises, a compromised device becomes a hostile endpoint,” said Vishnu Pratapagiri, Security Researcher at Zimperium and author of the analysis.

“DroidLock can intercept one-time passcodes, change device credentials, wipe data, and remotely control the user interface. Organizations need mobile security that stops these attacks before they disrupt operations or enable account takeover.”

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Network / IP
  • Mobile surveillance
  • Cyber security
  • Data Security
  • Related categories
  • Power supplies & batteries
  • Bollards
  • Barricades
  • Storage
  • Barriers
Related white papers
Aligning Physical And Cyber Defence For Total Protection

Aligning Physical And Cyber Defence For Total Protection

Download
Combining Security And Networking Technologies For A Unified Solution

Combining Security And Networking Technologies For A Unified Solution

Download
System Design Considerations To Optimize Physical Access Control

System Design Considerations To Optimize Physical Access Control

Download
Related articles
How Physical Security Consultants Ensure Cybersecurity For End Users

How Physical Security Consultants Ensure Cybersecurity For End Users

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

How Managed Detection And Response Enhances Cybersecurity Management In Organizations

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Drawbacks Of PenTests And Ethical Hacking For The Security Industry

Follow us

Sections Products Video Surveillance Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cybersecurity special report Casino security & surveillance RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Cyber security Counter terror Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy Californian Residents (CCPA)
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Corporate news
About this page

Zimperium zLabs reveals DroidLock, an advanced Android malware in Spain, executing screen-locking overlays, credential theft, and remote control. Safeguard against this ransomware threat targeting mobile device security.

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SecurityInformed.com - Making The World A Safer Place
Copyright © Notting Hill Media Inc. 2000 - 2025, all rights reserved

Our other sites:
SourceSecurity.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
One System, One Card
One System, One Card
Understanding AI-Powered Video Analytics
Understanding AI-Powered Video Analytics
Security And Surveillance Technologies For The Casino Market
Security And Surveillance Technologies For The Casino Market
Modernizing Access Control
Modernizing Access Control
Sign up now for full access to SecurityInformed.com content
Download Datasheet
Download PDF Version
Download SecurityInformed.com product tech spec