Congur Android Ransomware
Congur is Android ransomware that steals sensitive information from infected devices and enrolls them into a Distributed Denial of Service (DDoS) botnet.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Congur is Android ransomware that steals sensitive information from infected devices and enrolls them into a Distributed Denial of Service (DDoS) botnet.
Threat details
Instead of encrypting the device like most ransomware, Congur will set a new PIN code on the device and then ask you to pay a ransom to unlock it.
While the device is locked, the remote attacker can use it to perform DDoS attacks and steal the call history, GPS data and text messages. This continues even if the new PIN code is obtained.
While the device is locked, the remote attacker can use it to perform DDoS attacks and steal the call history, GPS data and text messages. This continues even if the new PIN code is obtained.
Remediation advice
To avoid becoming infected with ransomware, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:41 pm