
Findings and evidence
Zimperium describes Android malware that combines surveillance capabilities with ransomware behavior. The report explicitly associates its file-encryption functionality with older Android versions and documents samples distributed through third-party file sharing.
Why it matters
A defensible case record must include Android version, device policy and granted permissions. Separate observed data access, encryption and extortion messages instead of reporting a single undifferentiated ransomware outcome.
Scope and limits
The described behavior depends on device and operating-system conditions. The presence of an APK does not establish that every capability executed or that all stored files were encrypted.
Primary source
Zimperium zLabs: original publication. Source published 2026-09-09. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.