Close Menu
  • Home
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • NFT
  • DeFi
  • Blockchain
  • Technology
  • Cryptocurrency
  • All Posts

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Yemenis Embrace DeFi as Sanctions Disrupt Traditional Banking: Report

Apr. 18, 2025

Non-KYC Exchange eXch to Shut Down Following Investigation into Alleged Connections with Lazarus Group

Apr. 18, 2025

Ethereum Transaction Fees Plummet to a 5-Year Low of Just $0.17 Per Transfer: Is Widespread Adoption on the Horizon?

Apr. 17, 2025
Facebook X (Twitter) Instagram
CeDiFi LoopCeDiFi Loop
  • Home
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • NFT
  • DeFi
  • Blockchain
  • Technology
  • Cryptocurrency
  • All Posts
Facebook X (Twitter) Instagram Pinterest Vimeo
Subscribe
CeDiFi LoopCeDiFi Loop
Home » New ‘Crocodilus’ Android Malware Compromises Sensitive Cryptocurrency Wallet Credentials: A Study
Blockchain

New ‘Crocodilus’ Android Malware Compromises Sensitive Cryptocurrency Wallet Credentials: A Study

By adminMar. 31, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
New 'Crocodilus' Android Malware Compromises Sensitive Cryptocurrency Wallet Credentials: A Study
New 'Crocodilus' Android Malware Compromises Sensitive Cryptocurrency Wallet Credentials: A Study
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research

A new “highly capable” mobile banking malware dubbed “Crocodilus,” targets Android devices, extorting sensitive crypto wallet credentials using social engineering tactics.

A recent research by cybersecurity firm Threat Fabric found the emergence of a new malware family Crocodilus. The malware is reportedly distributed through a proprietary dropper that bypasses Android 13+ restrictions.

“Despite being new, it already includes all the necessary features of modern banking malware: overlay attacks, keylogging, remote access, and ‘hidden’ remote control capabilities,” analysts noted.

Sophisticated Android malware designed to steal cryptocurrency private keys isn’t new. In October 2024, the FBI issued a warning about a similar malware called SpyAgent, which was linked to North Korean hackers.

However, what differs in the new mobile banking Trojan Crocodilus is the “device takeover and advanced credential theft,” Threat Fabric wrote on X.

Crocodilus Displays Overlays to Target Banks and Cryptos

Crocodilus malware works on a modus operandi similar to modern “Device Takeover banking Trojan,” analysts noted. After initial installation via a proprietary dropper, the malware requests “Accessibility Service” to be enabled, they added.

In order to intercept credentials, Crocodilus connects to the command-and-control (C2) server for instructions such as overlays to be used.

Further, the threat initially appeared in Spain and Turkey, targeting several crypto wallets, the Mobile Threat Intelligence team revealed.

“We expect this scope to broaden globally as the malware evolves,” the team noted.

Additionally, the two-factor authentication (2FA) is bypassed by the malware using RAT command that triggers a screen capture on the content of the Google Authenticator application. Crocodilus captures the code displayed on the screen in the Google Authenticator app, and sends to the C2.

Malware Instructs Victims to Do the Job

Unlike other Trojans, Crocodilus overlays target crypto wallet by asking victims to take a backup of their wallet keys.

“Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet,” the overlay text reads.

This social engineering hack guides victims to navigate to their seed phrase. This in turn allows Crocodilus to extract the text using its Accessibility Logger.

“With this information, attackers can seize full control of the wallet and drain it completely,” Threat Fabric analysts said.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Non-KYC Exchange eXch to Shut Down Following Investigation into Alleged Connections with Lazarus Group

Apr. 18, 2025

Ethereum Transaction Fees Plummet to a 5-Year Low of Just $0.17 Per Transfer: Is Widespread Adoption on the Horizon?

Apr. 17, 2025

$FARTCOIN Set for Significant Breakout as Social Volume Increases by 450% at Critical Support Level

Apr. 17, 2025
Leave A Reply Cancel Reply

Top Posts

Consensys Seeks Extension for IRS Crypto Reporting Regulations

Jan. 1, 2023

Elon Musk’s OpenAI Troll Ignites Enthusiasm and Speculation within Crypto Community

Mar. 7, 2024

Restoration of Old Devices in Emerging Markets through Aphone, a Virtual Smartphone App on Solana

Mar. 8, 2024

Elon Musk to Make AI Chatbot Grok Open-Source Amid Ongoing OpenAI Lawsuit

Mar. 11, 2024
Don't Miss
DeFi

Yemenis Embrace DeFi as Sanctions Disrupt Traditional Banking: Report

Apr. 18, 2025

Yemenis Turn to DeFi as Sanctions Cut Off Traditional Banking: Report As financial sanctions and…

Non-KYC Exchange eXch to Shut Down Following Investigation into Alleged Connections with Lazarus Group

Apr. 18, 2025

Ethereum Transaction Fees Plummet to a 5-Year Low of Just $0.17 Per Transfer: Is Widespread Adoption on the Horizon?

Apr. 17, 2025

Over $120 Million Transferred to Solana in 30 Days, with $41.5 Million from Ethereum Leading the Contribution

Apr. 17, 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Website Introduction
Website Introduction

CeDiFi Loop is your gateway to the world of blockchain and Web3. We provide authoritative, in-depth coverage of cryptocurrency news and analysis, helping you understand the transformation and development of the digital asset world.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Yemenis Embrace DeFi as Sanctions Disrupt Traditional Banking: Report

Apr. 18, 2025

Non-KYC Exchange eXch to Shut Down Following Investigation into Alleged Connections with Lazarus Group

Apr. 18, 2025

Ethereum Transaction Fees Plummet to a 5-Year Low of Just $0.17 Per Transfer: Is Widespread Adoption on the Horizon?

Apr. 17, 2025
Most Popular

Consensys Seeks Extension for IRS Crypto Reporting Regulations

Jan. 1, 2023

Elon Musk’s OpenAI Troll Ignites Enthusiasm and Speculation within Crypto Community

Mar. 7, 2024

Restoration of Old Devices in Emerging Markets through Aphone, a Virtual Smartphone App on Solana

Mar. 8, 2024
  • Home
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • NFT
  • DeFi
  • Blockchain
  • Technology
  • Cryptocurrency
  • All Posts
© 2025 CeDiFi Loop All rights reserved.

Type above and press Enter to search. Press Esc to cancel.