Skip to content

AndroCrypt is a ransomware built for Android 14+ devices. It implements a full file encryption and decryption system with key management, supports remote server communication for handling keys or commands, and offers extensive customization to adapt behavior and configuration.

License

Notifications You must be signed in to change notification settings

Sh1r0ko11/AndroCrypt

Repository files navigation

AndroCrypt

android-14-376844

AndroCrypt - Android Ransomware

Android Security Educational

Easy Encryption

⚠️ Important Warning: This is strictly for learning and research purposes only! ⚠️

What is AndroCrypt?

AndroCrypt is a Android ransomware that shows how modern ransomware operates on newer Android devices (version 14 and up). It fully encrypts mostly every file on the Device

What Can It Do?

The Main Features

  • File Encryption: Locks up your files using strong AES-256 encryption
  • Screen Locking: Takes over your screen so you can't use your phone
  • Fast Processing: Encrypts files quickly without slowing down the device
  • Proper Decryption: Can actually unlock your files with the right key
  • Server Reporting: Sends infection details to a monitoring server (C&C) or webhook (TCP OR HTPPS)
  • Decryption key system sends Decryption key from specific infected device ID to a server(C&C) or webhook
  • Decryption key system 2 automatically generates a random decryption key that will get send to your server(C&C)/webhook.
  • Startup The AndroCrypt software starts on boot so even if the device is shutdown or rebooted it will continue displaying the ransom message screen
  • Security Security features, were trying to keep our APP safe against malware researchers and people that want to decrypt without having to pay

Files It Can Encrypt

Basically, it goes after all the important stuff:

  • Documents (PDF, Word, Excel, text files)

  • Photos and images (JPG, PNG, etc.)

  • Videos and music files

  • Zip files and archives

  • Even app files and databases

  • full supported encryption file extensions here: File_extensions

Stealing? what does this mean?

AndroCrypt is one of the first Android Ransomwares that Steals passwords from phones, Browser Data and Basic Information. We designed it to be powerful and easy. Our app isnt just ,,any,, App, its one of the most powerful free Open-Source available. its steals like no other.

We Make Things Easy 🌟

Smooth Experience, Instant Trust

We design our app to feel like familiar, trusted software from the very first use. The experience is so natural and intuitive that users feel immediately comfortable, while everything works seamlessly in the background.

A Step-by-Step Look

1: The Permission Trap

First the app sweet-talks the user into giving it the keys to the kingdom. It presents itself as a helpful tool that needs special access to "optimize" the device.

The app requesting permissions

2: The Fake Cleanup

Once it has access the app puts on a convincing show. It displays a progress bar that makes it look like its hard at work cleaning up junk files and optimizing performance. This is all theater designed to make the user feel like everything is working perfectly.

The fake cleanup screen

3: The Reveal

The curtain drops. After the fake cleanup "finishes" the user is greeted with the ransom note. Their files are encrypted, screen is locked and the app makes it clear that paying up is the only way out.

AndroCryptRansomScreen

Device Layout:

Screenshot 2025-10-12 220856

Tools and requirements you need

  • Kotlin
  • python 3.11
  • Java
  • AndroidStudio
  • VSC (recommended but no must)

About

AndroCrypt is a ransomware built for Android 14+ devices. It implements a full file encryption and decryption system with key management, supports remote server communication for handling keys or commands, and offers extensive customization to adapt behavior and configuration.

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published