Close Menu
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Bitcoin traders blamed Saylor’s 32 BTC sale but larger selling pressure built elsewhere

June 5, 2026

You Will Not Like Where Google Gemini AI Predicts Bitcoin Going in The Next 30 Days

June 5, 2026

The Bitcoin Crash Just Wiped $62 Billion From Corporate Treasury Holders, Is the MicroStrategy Model Broken?

June 5, 2026
Facebook X (Twitter) Instagram
CredBit.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
CredBit.com
Home » New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research
Crypto News

New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research

March 31, 20253 Mins Read
Facebook Twitter WhatsApp Pinterest Telegram LinkedIn Tumblr Email Reddit VKontakte
New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research
Share
Facebook Twitter LinkedIn Pinterest Telegram Email

A new “highly capable” mobile banking malware dubbed “Crocodilus,” targets Android devices, extorting sensitive crypto wallet credentials using social engineering tactics.

A recent research by cybersecurity firm Threat Fabric found the emergence of a new malware family Crocodilus. The malware is reportedly distributed through a proprietary dropper that bypasses Android 13+ restrictions.

“Despite being new, it already includes all the necessary features of modern banking malware: overlay attacks, keylogging, remote access, and ‘hidden’ remote control capabilities,” analysts noted.

Sophisticated Android malware designed to steal cryptocurrency private keys isn’t new. In October 2024, the FBI issued a warning about a similar malware called SpyAgent, which was linked to North Korean hackers.

However, what differs in the new mobile banking Trojan Crocodilus is the “device takeover and advanced credential theft,” Threat Fabric wrote on X.

A new mobile banking Trojan has emerged—#Crocodilus. Discovered during regular threat hunting, it’s already showing capabilities that rival top malware families, including device takeover and advanced credential theft.https://t.co/RlyfFxUYHe#BankingTrojan #ThreatFabric pic.twitter.com/47zPbPfFad

— ThreatFabric (@ThreatFabric) March 28, 2025

Crocodilus Displays Overlays to Target Banks and Cryptos

Crocodilus malware works on a modus operandi similar to modern “Device Takeover banking Trojan,” analysts noted. After initial installation via a proprietary dropper, the malware requests “Accessibility Service” to be enabled, they added.

In order to intercept credentials, Crocodilus connects to the command-and-control (C2) server for instructions such as overlays to be used.

Further, the threat initially appeared in Spain and Turkey, targeting several crypto wallets, the Mobile Threat Intelligence team revealed.

“We expect this scope to broaden globally as the malware evolves,” the team noted.

Additionally, the two-factor authentication (2FA) is bypassed by the malware using RAT command that triggers a screen capture on the content of the Google Authenticator application. Crocodilus captures the code displayed on the screen in the Google Authenticator app, and sends to the C2.

Malware Instructs Victims to Do the Job

Unlike other Trojans, Crocodilus overlays target crypto wallet by asking victims to take a backup of their wallet keys.

“Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet,” the overlay text reads.

This social engineering hack guides victims to navigate to their seed phrase. This inturn allows Crocodilus to extract the text using its Accessibility Logger.

“With this information, attackers can seize full control of the wallet and drain it completely,” Threat Fabric analysts said.

The post New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research appeared first on Cryptonews.


Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Reddit VKontakte Telegram WhatsApp

Related Posts

You Will Not Like Where Google Gemini AI Predicts Bitcoin Going in The Next 30 Days

June 5, 2026

The Bitcoin Crash Just Wiped $62 Billion From Corporate Treasury Holders, Is the MicroStrategy Model Broken?

June 5, 2026

Arthur Hayes Just Dumped His Entire Zcash Position After a Bug That Could Have Allowed Counterfeit ZEC for 4 Years

June 5, 2026

Ethereum News Today: BitMine to Raise $300M in Preferred Stock to Buy ETH

June 5, 2026

Can Elon Musk Grok AI Be Right About This Scary 2026 XRP Price Prediction?

June 4, 2026

Sam Altman ChatGPT AI Predicts Wild Bitcoin Price by End of 2026

June 4, 2026

Comments are closed.

Editors Picks

Bitcoin traders blamed Saylor’s 32 BTC sale but larger selling pressure built elsewhere

June 5, 2026

You Will Not Like Where Google Gemini AI Predicts Bitcoin Going in The Next 30 Days

June 5, 2026

The Bitcoin Crash Just Wiped $62 Billion From Corporate Treasury Holders, Is the MicroStrategy Model Broken?

June 5, 2026

Arthur Hayes Just Dumped His Entire Zcash Position After a Bug That Could Have Allowed Counterfeit ZEC for 4 Years

June 5, 2026
© 2026 - credbit.com - All Rights Reserved!
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.