← Back to Feed

New Android malware encrypts files, steals data, and harasses victims

September 10, 2026 · BleepingComputer · Severity: CRITICAL

A new Android malware variant has been discovered that encrypts files, steals data, and has ransomware capabilities, locking devices and demanding ransom payments. It spreads through malicious apps disguised as legitimate software on third-party app stores. This malware poses a dual threat of data theft and extortion, emphasizing the need for cautious app installation.

Key Takeaways

  • A new Android malware variant has been discovered that encrypts files, steals data, and has ransomware capabilities, locking devices and demanding ransom payments. It spreads through malicious apps disguised as legitimate software on third-party app stores. This malware poses a dual threat of data theft and extortion.
  • The malware can exfiltrate sensitive information such as contacts, messages, and photos before encrypting files, increasing the pressure on victims to pay. It uses social engineering to trick users into granting permissions, enabling full device compromise. Users should avoid sideloading apps and use security software.
  • This Android malware highlights the growing trend of multi-functional threats that combine data theft with ransomware. The use of third-party app stores as distribution vectors underscores the risks of unofficial sources. Android users should stick to the Google Play Store and enable Play Protect for added security.
☕ Buy a Coffee