COVID-19 contact tracing ransomware scheme exposed, be careful out there - Android

Get it on Google Play

COVID-19 contact tracing ransomware scheme exposed, be careful out there - Android

Ransomware apps for Android are already out in the wild disguised as contact tracing apps for the COVID-19 pandemic.

Huawei Mate 30 Pro Google Play store

Credit: Ryan-Thomas Shaw / Android Authority


  • A ransomware program disguised as a contact tracing app went out into the wild recently.
  • Luckily, the app was found and shut down quickly, so it likely didn’t affect many people.
  • However, more programs like this are sure to surface, so pay attention to the warning signs detailed here.



When Google and Apple announced they would be working together to create an API for future COVID-19 contact tracing apps, it was big news. Predictably, malicious hackers are already capitalizing on the news by creating ransomware apps that pose as a contact tracing app.

One such example happened just recently in Canada. On the same day that Canadian Prime Minister Justin Trudeau announced a voluntary nationwide contact tracing app, hackers compiled a ransomware app known as CryCryptor. The Android app encrypts important user files on a device and gives instructions on how to undo the encryption by paying the hackers.

Related: 10 best security apps for Android that aren’t anti-virus apps

Luckily, the security research team at ESET figured out the scheme. While CryCryptor may not be too prevalent a threat at the moment, that doesn’t mean ransomware of this type won’t be a big problem. You should read on to learn about how this was done so you can avoid it happening to you.

CryCryptor ransomware: How does it work?

For CryCryptor to work properly, the hackers are depending on one major thing: the user allowing the installation of apps from outside the Google Play Store. If you have never done this before or are certain that your phone is set to never install outside applications, you already are safe from this particular type of ransomware.

However, for people who don’t have their phone locked down in this manner, here’s how CryCryptor works:

  1. A user visits an official-looking website that has a Google Play Store link to download a contact tracing app. The user clicks the link.
  2. Instead of going to the Play Store, the link downloads an APK file directly to the user’s device. It then asks if the user wants to install it.
  3. If the user has previously allowed apps from outside the Play Store, the installation will go smoothly.
  4. When the user launches the app they think is for contact tracing, the ransomware process begins. CryCryptor immediately starts encrypting important files on the phone.
  5. In every top-level folder that gets encrypted, a new text file appears labeled as “readme_now.txt”. In that file are brief instructions on how to email the hackers to unencrypt the files.
  6. Unless the user pays up or decrypts the files themselves, their data is locked away for good.

Two of the websites that ESET found were hosting CryCryptor have already been shut down. However, it’s only a matter of time before other hackers take the same principle behind this ransomware and bring it to other sites.

Thankfully, ESET developed a decrypting tool for CryCryptor. You can read all about that here.

The golden rule, though, is to never download anything from outside the Play Store unless you are 100% certain it is from a legitimate source. It’s not worth the risk!

More posts about Security

This is the featured image for the best find my phone apps for android

5 best find my phone apps and other find my phone methods too!

Vivo nex 3 5g rear camera module 5

Duplicates abound: Over 13,000 phones from one OEM share the same IMEI number

Redmi Note 7S showing lockscreen

Judge rules federal officials just checking your lock screen counts as a search

how to find a lost phone find my device google pixel 4 xl location map 2

What should you do when your phone is lost or stolen?

Motorola Edge camera macro 3

Motorola’s promise of just one major update for the Edge Plus is unacceptable

best free VPN apps for android

15 best Android VPN apps to recover your online anonymity

Xiaomi Mi 10 Pro google apps

How to hide apps, photos, and files on Android devices

Tiktok on the Google Play Store.

These developers just hacked the TikTok app with a DNS attack

This is the featured image for the best security apps for android

10 best security apps for Android that aren’t antivirus apps

A photograph of Google Play Protect functioning in the Googlel Play Store

15 best antivirus apps and best anti-malware apps for Android!

24/06/2020 06:44 PM