CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Crocodilus Malware Has Been Draining Crypto Wallets on Android
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Crocodilus Malware Has Been Draining Crypto Wallets on Android
News

Crocodilus Malware Has Been Draining Crypto Wallets on Android

CoinRSS
Last updated: April 1, 2025 3:18 am
CoinRSS Published April 1, 2025
Share

Contents
Who is Crocodilus targeting?Daily Debrief Newsletter

Android users beware: A newly discovered piece of malware is targeting smartphone crypto wallets.

Uncovered by fraud prevention firm ThreatFabric, the “Crocodilus” mobile banking trojan employs tools including remote control, black screen overlays, and advanced data harvesting through accessibility logging to trick crypto holders into handing over their wallet seed phrase.

The malware “is masquerading as crypto-related apps and involves specific social engineering techniques to make victims reveal the secrets stored inside cryptocurrency wallet applications,” Aleksandar Eremin, head of mobile threat intelligence at ThreatFabric, told Decrypt. He added that it’s pointing to the “specific interest of the actors behind it in targeting users of cryptocurrency wallets.”

Crucially, this threat tricks Android users into providing the seed phrase for their own cryptocurrency wallet. It does this by issuing a warning that asks users to back up their key to avoid losing access.

ThreatFabric said Crocodilus is being distributed through a proprietary dropper that bypasses security protections on Android 13 or later.

Once this dropper installs the malware, without triggering Play Protect, it requests Accessibility Service permissions. That allows it to bypass the Accessibility Service restrictions, enabling it to deploy a screen overlay to gain passwords.

The malware shows users a fake warning message that reads: “Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet.”

Crocodilus also works as a remote access trojan (RAT), meaning operators can navigate the user interface, swipe using gesture control and even take screenshots. According to ThreatFabric, this allows the malware operator to use Google Authenticator to access two-factor authentication passcodes.

The malware does all this discreetly by using a black screen overlay, so the phone owner can’t actually see what actions are being carried out remotely.

Who is Crocodilus targeting?

At time of publishing it appears that only users in Spain and Turkey have been affected by Crocodilus. The malware was first discovered targeting people in Turkey and Spain, and uses debug language that appears to be in Turkish.

How that initial dropper is downloaded is less clear, according to ThreatFabric, so it could well spread beyond these locations.

According to ThreatFabric, users are tricked into downloading the droppers through malicious sites, social media, fake promotions, text messages and third-party app stores. Android users can mitigate against the risk by only using the Google Play Store to download apps, and not downloading APKs from other sites.

Eremin told Decrypt that despite being a “newcomer to the mobile threat landscape,” Crocodilus’ “rich set of capabilities” could make it a competitor to established malware-as-a-service on underground markets.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

Solana DEX volume crosses $100B: What’s next for SOL prices?

XRP Futures Open Interest dives to 2025 low — Are traders abandoning Altcoin bets?

MicroStrategy’s Nasdaq Debut Could Trigger $2.1 Billion ETF Buying Spree

Ethereum Gaming Project CyberKongz Says SEC Has Ended Investigation

Bitcoin’s 27K outflows signal risk! – Examining odds of a possible correction

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Ethereum still lags behind Bitcoin, Solana, XRP: Will ETH’s fortunes turn?
Next Article Ethereum NFT Marketplace X2Y2 to Shut Down as Team Shifts to AI
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Bitcoin Rally Wavers as Trump Drops 50% EU Tariff Bombshell
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?