Pay a $300 fine or else your Android phone will be locked

by: William Neilson JrMay 8, 2014

Android Ransomware Ars Technica

Ars Technica alerts us to research that has uncovered Android-based malware that disables infected handsets until the users pay a cash payment to for their viewing of illegal pornography:

“The malware is automatically downloaded when people visit certain pornography sites using an Android phone. The sites then claim that the APK installs a video player used for premium access. To be infected, a user must change Android settings to allow out-of-market apps and then manually install the APK.”

Using the logo of the FBI and President Barack Obama, Android-Trojan.Koler.A uses a location function to tailor the warnings to whatever country that you reside in. The malware prevents users from accessing the home screen of their phones, making it impossible to use most other apps installed on the phone.

In some cases, a phone can be restored only when you pay a so-called “fine” of about $300, using payment services such as Paysafecard or uKash that are incredibly difficult to trace. Thankfully, there is no evidence that the malware encrypts any files on a phone’s storage.

The malware has already claimed at least 68 victims in the past six hours:

  • 40 in the United Arab Emirates
  • 12 in the UK, six in Germany
  • 5 in the US
  • Others in Italy and Poland

Almost two years ago, Symantec found that malware extorts an estimated $5 million a year from users through devices that become unusable and often display logos of local law-enforcement agencies, along with warnings that the user has violated statutes involving child pornography or other serious offenses. The warnings then offer to unlock the computers if users pay a fine as high as $200 within 72 hours. The report identified at least 16 different ransomware versions spawned by competing malware gangs.

More recently, scammers have built strong cryptography into malware, known as Cryptolocker, that holds entire hard drives hostage until end users pay a Bitcoin ransom of around $300.

Ransomware Kiandra

These issues are another reminder that Android users are being targeted by the malware and social engineering attacks.


  • Just asking, how difficult would it be to swipe down, open the flip settings, then tap on Settings and uninstall it from the Apps menu?

    • John

      I’m only reading this because it just happened to me and I tried this. It doesn’t open. It doesn’t even let you turn off your phone. You have to take the battery out. I was like “DUDE THE ACTORS ARE OVER 18 WHAT THE FUCK I DIDN’T KNOW IT’S NOT MY FAULT PORNHUB POSTED AN ILLEGAL VIDEO. THE VIEWER DON’T KNOW ANYTHING ABOUT THE PEOPLE THEY’RE WATCHING HAVING SEX!”

  • Josh Johnson

    This is why a nandroid backup is so helpful. I’d reboot into recovery and be done with it. Nice try

    • KingofPing

      status-bar pulldown – jump to settings, uninstall app.


      • Annie

        I’m reading all these comments and obviously nobody on here has had this happen. I checked my phone this morning and this carp is there. It locks your phone. No status bar, no settings, none of that. You can’t access anything, can’t get into your settings, can’t reboot the phone. You can’t do any of the carp people are suggesting.
        I let my brother use my phone for one day because his died, as in he dropped it in the sink. All these comments are basically saying that if you dont know how to fix it your stupid, but this thing locks your phone, making it impossible to do any of the things you guys are suggesting.

        • David Tupponce

          Not true. Press and hold power, volume down and home button on most Android phones to get to menu and do a factory reset ! Just got paid for fixing someone’s phone by using this method.

    • Annie

      Except for the part where you can’t access anything. Wtf is wrong with you people? Can’t you read? It locks your f***ing phone!! I have been trying to factory reset for the last thirty minutes. And all because my brothers an a**hole!! This thing won’t let me access the settings, as somebody so helpfully suggested, or the status bar as somebody else suggested. It won’t let you do anything.

      • Corey Watford

        Power down, boot into recovery and factory reset if you can’t uninstall it via status bar

      • Aditya Bhatt

        You don’t need to access your phone’s settings to do a reset always. You can boot into recovery mode of your phone and just select the option wipe data or factory reset.

    • David Tupponce

      exactly !

    Power down, boot into recovery and factory reset if you can’t uninstall it via status bar

