New ransomware masquerades as COVID-19 contact-tracing app on your Android device

New ransomware masquerades as COVID-19 contact-tracing app on your Android device 1

A new strain of ransomware is being deployed in attacks created off the back of the release of contact-tracing apps during the novel coronavirus pandemic

Researchers from ESET said this week that the ransomware emerged only a few days after Health Canada announced the release of COVID Alert, which will first be tested in Ontario before rolling out nationwide.

While the official app is not due to be made available to mobile device users until next month at the earliest, cyberattackers are trying to capitalize on the government’s announcement with an Android package of their own — marketed as Canada’s official COVID-19 tracing app, but hiding a malicious secret. 

According to the cybersecurity firm, two websites offered what appeared to be Health Canada’s tracing app. However, the now-defunct domains — tracershield[.]ca and covid19tracer[.]ca — were actually hosting APKs that, when downloaded, installed the CryCryptor ransomware on Android devices. 

Coinbase 3

The ransomware first came to ESET’s attention by way of a tweet by a Twitter user under the handle @ReBensk. While the alert warned that the APKs were hiding a banking Trojan, upon further examination, the malware turned out to be the new ransomware. 

See also: New WastedLocker ransomware demands payments of millions of USD

If an Android user downloads the APK from the fraudulent domains and installs the app, the malware requests access to files and begins the task of encrypting content on the device with specific extensions, including .PNG. 

.ENC is appended to compromised files, which are encrypted using AES and a 16-character key. A text file making a ransom demand is also left in each directory where encrypted files are stored. 

ESET has been able to create a decryption tool for the current version of the Android malware which has been made available on GitHub. 

It was possible to do so as the ransomware takes advantage of a bug categorized as “Improper Export of Android Components” (CWE-926) by MITRE. This issue allows installs apps to launch exported services, but in turn, this meant that a tool could be created that launches CryCryptor’s own decryption functions. 

CNET: Republicans push bill requiring tech companies to help access encrypted data

Furthermore, the ransomware was traced back to GitHub after its source code was made public on 11 June. According to ESET, the developer — who named the open source malware CryDroid — disguised the release as a research project. 

“We dismiss the claim that the project has research purposes — no responsible researcher would publicly release a tool that is easy to misuse for malicious purposes,” ESET says.

TechRepublic: Only 31% of Americans concerned with data security, despite 400% rise in cyberattacks

As the team was not convinced, GitHub has been made aware of the code’s true nature. 

Earlier this month, researchers said a new ransomware variant that appeared on the scene in May is being exclusively used in attacks against US companies. Thought to be the work of Evil Corp, the WastedLocker ransomware typically demands ransom payments reaching millions of dollars. 

Previous and related coverage

Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0

New ransomware masquerades as COVID-19 contact-tracing app on your Android device 2
About the author

E-Crypto News was developed to assist all cryptocurrency investors in developing profitable cryptocurrency portfolios through the provision of timely and much-needed information. Investments in cryptocurrency require a level of detail, sensitivity, and accuracy that isn’t required in any other market and as such, we’ve developed our databases to help fill in information gaps.

Related Posts


E-Crypto News Executive Interviews


Bitcoin (BTC) $ 41,603.00
Ethereum (ETH) $ 2,463.23
Tether (USDT) $ 0.998285
Binance Coin (BNB) $ 333.12
Cardano (ADA) $ 1.31
XRP (XRP) $ 0.752829
Dogecoin (DOGE) $ 0.210436
USD Coin (USDC) $ 0.999681
Polkadot (DOT) $ 16.41
Binance USD (BUSD) $ 0.999884
bitcoinBitcoin (BTC)
$ 41,603.00
ethereumEthereum (ETH)
$ 2,463.23
tetherTether (USDT)
$ 0.998285
bitcoin-cashBitcoin Cash (BCH)
$ 544.95
litecoinLitecoin (LTC)
$ 143.76
bitcoinBitcoin (BTC)
ethereumEthereum (ETH)
tetherTether (USDT)
bitcoin-cashBitcoin Cash (BCH)
litecoinLitecoin (LTC)
bitcoinBitcoin (BTC)
ethereumEthereum (ETH)
tetherTether (USDT)
bitcoin-cashBitcoin Cash (BCH)
litecoinLitecoin (LTC)

Automated trading with HaasBot Crypto Trading Bots

Crypto Scams

Hacks and Scam
The World’s Most Infamous Crypto Hacks and Scams
July 31, 2021
Cryptocurrency Exchanges
Cryptocurrency Exchanges and the Plague of Scams and Bans
June 29, 2021
What Role Do Cryptocurrencies Play In The Era Of Ransomware Attacks?
June 9, 2021
Crypto Scams On The Rise As Market Enters Bull Cycle
Crypto Scams On The Rise As Market Enters Bull Cycle
December 22, 2020
Harpreet Singh Sahni perpetrated the Plus Gold Union Coin (PGUC) scam
Sydney Concert Promoter Harpreet Sahni Involved In $50M Crypto PGUC Scam
November 2, 2020

Blockchain/Cryptocurrency Questions and Answers

Short-Sell Cryptocurrency
How to Short-Sell Cryptocurrency: A Brief Overview
July 17, 2021
What Is Klaytn (KLAY) And How Does It Work?
July 16, 2021
Our Crypto Roundup Interview Asks- Do Cryptocurrencies Have a Future?
July 15, 2021
What Is Solana (SOL) And How Does It Work?
June 26, 2021
What Is Plethori Platform And How Does It Work?
June 12, 2021

CryptoCurrencyUSDChange 1hChange 24hChange 7d
Bitcoin41,575 0.44 % 7.29 % 24.27 %
Ethereum2,456.9 0.35 % 4.99 % 16.05 %
Tether1.000 0.21 % 0.05 % 0.20 %
Binance Coin332.16 0.23 % 7.32 % 11.60 %
Cardano1.310 0.78 % 3.82 % 8.75 %
XRP0.7517 0.17 % 4.07 % 23.34 %
Dogecoin0.2095 0.70 % 4.34 % 8.18 %
USD Coin0.9992 0.13 % 0.05 % 0.16 %
Polkadot16.31 0.80 % 11.31 % 22.15 %
Binance USD0.9984 0.18 % 0.05 % 0.56 %

Bitcoin (BTC) $ 41,916.00
Ethereum (ETH) $ 2,575.11
Tether (USDT) $ 1.00
Binance Coin (BNB) $ 340.96
Cardano (ADA) $ 1.35
XRP (XRP) $ 0.761132
Dogecoin (DOGE) $ 0.217852
USD Coin (USDC) $ 1.00
Polkadot (DOT) $ 18.41
Binance USD (BUSD) $ 1.00