Skip to main content

New 'El Gato' Android ransomware may sound cute, but it packs a punch

el gato android ransomware cat
Flickr/Jarjav CC
A killer software cat may be coming for your text messages, according to a threat report by McAfee Labs Mobile Malware Research team. It’s been dubbed “El Gato” — “The Cat,” in Spanish — because the Android malware’s code contains, of all things, an image of a yowling tabby.

McAfee discovered an instance of El Gato running on a compromised server, but noted that it appeared inert — it wasn’t password protected, and “included code words such as MyDifficultPassw.” 

Unlike the pictured kitty, El Gato is anything but cute and cuddly. The malicious software is a form of ransomware, code that renders a device unusable until the victim forks over money. This one is particularly sophisticated, from the sound of it — El Gato can encrypt files, steal text messages, and even “block access” to the affected handset or tablet entirely.

El Gato accomplishes most of its nasty shenanigans remotely, via a connection with an offshore server. It constantly monitors an infected device’s internet connection for commands and, once it receives them, executes on them. Among the most common functions McAfee’s researchers discovered were sending messages from the infected device, forwarding and deleting text messages, locking the device’s screen, and crashing a specific application. Worryingly, it’s capable of performing many of those tasks clandestinely, in the background, making them effectively invisible to victims.

The image contained in El Gato's code.
The image contained in El Gato’s code. Image used with permission by copyright holder

Most of El Gato’s commands are dispatched through a surprisingly polished web-based interface, said McAfee. They can be executed in sequence or individually — stealing a text message, frighteningly, is as easy as clicking a button in a web browser.

Perhaps worse yet, El Gato is capable of encrypting all files on the device’s internal storage — rendering it essentially unusable without the randomly generated password it generates. It contains a means of reversing the damage — the malware has can decrypt any file it secures — but presumably only after an affected user hands over whatever form of payment the attacker demands.

There’s good news, though: as far as malware goes, El Gato is relatively harmless. It hasn’t been observed in the wild yet, and its traffic is entirely unencrypted, making it susceptible to countermeasures. In other words, El Gato’s commands could be intercepted, isolated, and rendered harmless.

El Gato may be the latest instance of ransomware to emerge on Android, but it’s hardly the first. In May, cybersecurity analysts at Malwarebytes Labs discovered Cyber.Police, a malicious app that displayed a countdown timer, threatening message, and an explicit pornographic image to victims. It demanded that users purchase iTunes gift cards in exchange for an unlock code — a component which El Gato thankfully lacks, as of yet.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
AT&T just made it a lot easier to upgrade your phone
AT&T Storefront with logo.

Do you want to upgrade your phone more than once a year? What about three times a year? Are you on AT&T? If you answered yes to those questions, then AT&T’s new “Next Up Anytime” early upgrade program is made for you. With this add-on, you’ll be able to upgrade your phone three times a year for just $10 extra every month. It will be available starting July 16.

Currently, AT&T has its “Next Up” add-on, which has been available for the past several years. This program costs $6 extra per month and lets you upgrade by trading in your existing phone after at least half of it is paid off. But the new Next Up Anytime option gives you some more flexibility.

Read more
Motorola is selling unlocked smartphones for just $150 today
Someone holding the Moto G Stylus 5G (2024).

Have you been looking for phone deals but don’t want to spend a ton of money on flagship devices from Apple and Samsung? Have you ever considered investing in an unlocked Motorola? For a limited time, the company is offering a $100 markdown on the Motorola Moto G 5G. It can be yours for just $150, and your days and nights of phone-shopping will finally be over!

Why you should buy the Motorola Moto G 5G
Powered by the Snapdragon 480+ 5G CPU and 4GB of RAM, the Moto G delivers exceptional performance across the board. From UI navigation to apps, games, and camera functions, you can expect fast load times, next to no buffering, and smooth animations. You’ll also get up to 128GB of internal storage that you’ll be able to use for photos, videos, music, and any other mobile content you can store locally. 

Read more
The Nokia 3210 is the worst phone I’ve used in 2024
A person holding the Nokia 3210, showing the screen.

Where do I even start with the Nokia 3210? Not the original, which was one of the coolest phones to own back in a time when Star Wars: Episode 1 -- The Phantom Menace wasn’t even a thing, but the latest 2024 reissue that has come along to save us all from digital overload, the horror of social media, and the endless distraction that is the modern smartphone.

Except behind this facade of marketing-friendly do-goodery hides a weapon of torture, a device so foul that I’d rather sit through multiple showings of Jar Jar Binks and the gang hopelessly trying to bring back the magic of A New Hope than use it.
The Nokia 3210 really is that bad

Read more