• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Crocodilus Malware Has Been Draining Crypto Wallets on Android

admin by admin
April 25, 2025
in Analysis
0
Crocodilus Malware Has Been Draining Crypto Wallets on Android
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Android users beware: A newly discovered piece of malware is targeting smartphone crypto wallets.

Uncovered by fraud prevention firm ThreatFabric, the “Crocodilus” mobile banking trojan employs tools including remote control, black screen overlays, and advanced data harvesting through accessibility logging to trick crypto holders into handing over their wallet seed phrase.

Related articles

ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025

The malware “is masquerading as crypto-related apps and involves specific social engineering techniques to make victims reveal the secrets stored inside cryptocurrency wallet applications,” Aleksandar Eremin, head of mobile threat intelligence at ThreatFabric, told Decrypt. He added that it’s pointing to the “specific interest of the actors behind it in targeting users of cryptocurrency wallets.”

Crucially, this threat tricks Android users into providing the seed phrase for their own cryptocurrency wallet. It does this by issuing a warning that asks users to back up their key to avoid losing access.

ThreatFabric said Crocodilus is being distributed through a proprietary dropper that bypasses security protections on Android 13 or later.

Once this dropper installs the malware, without triggering Play Protect, it requests Accessibility Service permissions. That allows it to bypass the Accessibility Service restrictions, enabling it to deploy a screen overlay to gain passwords.

The malware shows users a fake warning message that reads: “Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet.”

Crocodilus also works as a remote access trojan (RAT), meaning operators can navigate the user interface, swipe using gesture control and even take screenshots. According to ThreatFabric, this allows the malware operator to use Google Authenticator to access two-factor authentication passcodes.

The malware does all this discreetly by using a black screen overlay, so the phone owner can’t actually see what actions are being carried out remotely.

Who is Crocodilus targeting?

At time of publishing it appears that only users in Spain and Turkey have been affected by Crocodilus. The malware was first discovered targeting people in Turkey and Spain, and uses debug language that appears to be in Turkish.

How that initial dropper is downloaded is less clear, according to ThreatFabric, so it could well spread beyond these locations.

According to ThreatFabric, users are tricked into downloading the droppers through malicious sites, social media, fake promotions, text messages and third-party app stores. Android users can mitigate against the risk by only using the Google Play Store to download apps, and not downloading APKs from other sites.

Eremin told Decrypt that despite being a “newcomer to the mobile threat landscape,” Crocodilus’ “rich set of capabilities” could make it a competitor to established malware-as-a-service on underground markets.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



#Crocodilus #Malware #Draining #Crypto #Wallets #Android

Tags: 400 hot versus cold wallets400 the token launch receiveda m et bitcoinaccess to your walletAndroidbagged 6 556 btc for 555been draining crypto walletsCrocodiluscryptocrypto holders incrypto walletdogecoin dogeDraininggenerating btc on btc yield strongindex at 23 100 on aprilindian city of kolkata said kashmirmalwaremanagement aum continued to decline droppingmunich with five games remaining pmunicipal treasury according to statements sharedpaused historic rally stocks cryptoplatform will continue operations led byproposals as unacceptable with littlerise but most peoplethat bitcoin s weak performance reflectsthe secrets stored inside cryptocurrencyuntold numbers of us companies theyusers of cryptocurrencyWallets
Share76Tweet47

Related Posts

ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

by admin
May 28, 2025
0

In brief ASIC has filed civil charges against former Blockchain Global director Liang Guo over alleged misuse of ACX customer...

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

by admin
May 28, 2025
0

Six days after a $223 million exploit shook the Sui ecosystem, decentralized exchange Cetus has announced a recovery initiative that...

El Salvador Defies IMF Again With Fresh Bitcoin Purchase Following Loan Review

El Salvador Defies IMF Again With Fresh Bitcoin Purchase Following Loan Review

by admin
May 28, 2025
0

In brief El Salvador added eight more Bitcoin to its reserve despite IMF warnings An IMF agreement struck on Tuesday...

AI and Crypto Czar David Sacks Says the US Could Buy More Bitcoin

AI and Crypto Czar David Sacks Says the US Could Buy More Bitcoin

by admin
May 28, 2025
0

In brief AI and Crypto Czar David Sacks appeared at Bitcoin 2025 in Las Vegas on Tuesday. Sacks suggested that...

Ethereum Options Market Signals Cautious Optimism as Open Interest Climbs

Ethereum Options Market Signals Cautious Optimism as Open Interest Climbs

by admin
May 28, 2025
0

In brief Amberdata data shows only a 12% chance of ETH exceeding $5,000 by December 2025. Retail traders are targeting...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

May 28, 2025
Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com