detection icon

Short bio

Android/Ransom.SLocker is Malwarebytes’ detection name for a family of mobile ransomware.

Type and source of infection

Ransom.SLocker masquerades as various legitimate apps to fool users into accepting escalated rights. Users who accept the escalated rights will have their device forced to reboot.  After reboot, users will have their device locked with overlaying screen with instructions to pay.

ransom notice


You can protect yourself by being cautious before giving superuser and/or device administrator rights to any app that asks for it.


Malwarebytes Anti-Malware Mobile can remove the ransomware, but only before escalated rights have been granted. Afterwards, it becomes a bit harder. For how to remove such infections, refer to blog post “Difficulty removing Koler Trojan or other ransomware on Android?