Locker (Ransomware)
In short: A ransomware variant that doesn’t encrypt individual files but locks access to the entire device (e.g. the screen) and only unlocks it again in return for a ransom.
In more detail: Unlike crypto ransomware (which specifically encrypts files that remain unusable even after the malware has been removed), locker ransomware usually “only” blocks operation of the device itself — the data is often still technically intact but inaccessible without unlocking. More common on mobile devices than on classic PCs.
In Depth
The two big ransomware families compared:
Locker ransomware - locks OPERATION of the device (e.g. screen lock;
the data itself often stays unchanged), easier to
remove without data loss
Crypto ransomware - specifically encrypts individual files with strong
encryption; the data stays unusable without the key
even after the malware has been removed
Locker ransomware is historically the simpler, older variant and comparatively rarer today — because it can often be overcome without the demanded key (e.g. by restarting in safe mode, removing the malware, resetting to a backup of the system settings), it’s less lucrative for attackers than crypto ransomware. With crypto ransomware, the data stays unusable even when the actual malware has been completely removed — only the matching decryption key (which the attacker holds back) makes it usable again, which considerably increases the pressure to pay the ransom.
On mobile devices (especially older Android versions), locker ransomware was long more widespread than on classic PCs, because a simple app overlay across the entire screen is often enough to effectively block operation — complete file encryption is technically more complex to implement on mobile systems.
Typical procedure and deception patterns
Classic locker ransomware often uses psychological pressure as part of the attack: the lock screen often poses as an official notice from the authorities (e.g. a fake message from the police or FBI claiming that illegal content has been found on the device and demanding a “fine”) — this intimidation tactic is meant to get victims to pay quickly and rashly out of shame or fear, instead of seeking professional help or contacting the police. Well-known early representatives of this category were the “Reveton” trojan (from 2012, often called the “police trojan” or, in Germany, the “BKA trojan”) and similar variants, which used regionally adapted fake authority logos and texts.
Why paying is generally not a good idea
Security authorities and experts generally advise against paying a ransom — not only because it finances the criminal business model and makes further attacks more likely, but also because there’s no guarantee that an attacker will actually deliver the unlocking/decryption after payment. With locker ransomware the situation is often more favourable than with crypto ransomware: because the data itself usually stays unchanged, a restart in safe mode, a specialised rescue CD/USB boot environment or — on Android — removing the malicious app via the device manager is often enough to get around the lock without paying.
Modern development: hybrid approaches
Modern ransomware often combines both approaches and goes even further: besides the classic locking/encryption, many current variants additionally threaten “double extortion” — before the actual lock, sensitive data is first exfiltrated (copied) unnoticed, so that attackers can still exert pressure even if the victim restores from intact backups: if they don’t pay, the attackers threaten to publish the stolen data. This development shows why pure backup strategies alone are no longer considered complete ransomware protection today — prevention (patch management, 2FA, staff training) remains just as important as the ability to recover.
See also: Ransomware