How does the malware work?
Then, it starts encrypting the files stored on the infected devices external storage.
The ransomware uses AES encryption to lock the files (see code below).
in the path, or files that are bigger than 10 KB.
This is not much compared to what other mobile ransomware has demanded in the past.
This is, however, risky as the money can be easily traced, unlike when sending cryptocurrencies.
Additionally, Android users should refrain from downloading apps on any app marketplaces other than Google Play.
Source:IBT
Read More
source: www.techworm.net