• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Crocodilus Malware Has Been Draining Crypto Wallets on Android

admin by admin
April 25, 2025
in Analysis
0
Crocodilus Malware Has Been Draining Crypto Wallets on Android
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Android users beware: A newly discovered piece of malware is targeting smartphone crypto wallets.

Uncovered by fraud prevention firm ThreatFabric, the “Crocodilus” mobile banking trojan employs tools including remote control, black screen overlays, and advanced data harvesting through accessibility logging to trick crypto holders into handing over their wallet seed phrase.

Related articles

Global Darknet Bust Leads to 0M in Digital Asset and Cash Seizures

Global Darknet Bust Leads to $200M in Digital Asset and Cash Seizures

May 23, 2025
Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

May 23, 2025

The malware “is masquerading as crypto-related apps and involves specific social engineering techniques to make victims reveal the secrets stored inside cryptocurrency wallet applications,” Aleksandar Eremin, head of mobile threat intelligence at ThreatFabric, told Decrypt. He added that it’s pointing to the “specific interest of the actors behind it in targeting users of cryptocurrency wallets.”

Crucially, this threat tricks Android users into providing the seed phrase for their own cryptocurrency wallet. It does this by issuing a warning that asks users to back up their key to avoid losing access.

ThreatFabric said Crocodilus is being distributed through a proprietary dropper that bypasses security protections on Android 13 or later.

Once this dropper installs the malware, without triggering Play Protect, it requests Accessibility Service permissions. That allows it to bypass the Accessibility Service restrictions, enabling it to deploy a screen overlay to gain passwords.

The malware shows users a fake warning message that reads: “Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet.”

Crocodilus also works as a remote access trojan (RAT), meaning operators can navigate the user interface, swipe using gesture control and even take screenshots. According to ThreatFabric, this allows the malware operator to use Google Authenticator to access two-factor authentication passcodes.

The malware does all this discreetly by using a black screen overlay, so the phone owner can’t actually see what actions are being carried out remotely.

Who is Crocodilus targeting?

At time of publishing it appears that only users in Spain and Turkey have been affected by Crocodilus. The malware was first discovered targeting people in Turkey and Spain, and uses debug language that appears to be in Turkish.

How that initial dropper is downloaded is less clear, according to ThreatFabric, so it could well spread beyond these locations.

According to ThreatFabric, users are tricked into downloading the droppers through malicious sites, social media, fake promotions, text messages and third-party app stores. Android users can mitigate against the risk by only using the Google Play Store to download apps, and not downloading APKs from other sites.

Eremin told Decrypt that despite being a “newcomer to the mobile threat landscape,” Crocodilus’ “rich set of capabilities” could make it a competitor to established malware-as-a-service on underground markets.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



#Crocodilus #Malware #Draining #Crypto #Wallets #Android

Tags: 400 hot versus cold wallets400 the token launch receiveda m et bitcoinaccess to your walletAndroidbagged 6 556 btc for 555been draining crypto walletsCrocodiluscryptocrypto holders incrypto walletdogecoin dogeDraininggenerating btc on btc yield strongindex at 23 100 on aprilindian city of kolkata said kashmirmalwaremanagement aum continued to decline droppingmunich with five games remaining pmunicipal treasury according to statements sharedpaused historic rally stocks cryptoplatform will continue operations led byproposals as unacceptable with littlerise but most peoplethat bitcoin s weak performance reflectsthe secrets stored inside cryptocurrencyuntold numbers of us companies theyusers of cryptocurrencyWallets
Share76Tweet47

Related Posts

Global Darknet Bust Leads to 0M in Digital Asset and Cash Seizures

Global Darknet Bust Leads to $200M in Digital Asset and Cash Seizures

by admin
May 23, 2025
0

In brief Operation RapTor resulted in 270 arrests across 10 countries and the seizure of $200 million in cash and...

Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

Trump’s Meme Coin Dinner Draws Protests Calling For End to ‘Crypto Corruption’

by admin
May 23, 2025
0

In brief Protesters carried signs like "Grift Gala" and "America is not for sale" as Trump dined with $TRUMP token...

America’s Biggest Banks Consider Teaming Up to Challenge 5B Stablecoin Market: WSJ

America’s Biggest Banks Consider Teaming Up to Challenge $245B Stablecoin Market: WSJ

by admin
May 23, 2025
0

In brief Major U.S. banks, including JPMorgan and Bank of America, are reportedly exploring a shared stablecoin project. The move...

Anthropic’s Claude 4 Arrives, Obliterating AI Rivals—And Budgets Too

Anthropic’s Claude 4 Arrives, Obliterating AI Rivals—And Budgets Too

by admin
May 23, 2025
0

In brief Claude 4 finally launched after long delays, crushing GPT-4.1 and Gemini 2.5 Pro on SWE-bench coding benchmarks. The...

YGG Launches New Publishing Arm, Debuts First Game ‘LOL Land’

YGG Launches New Publishing Arm, Debuts First Game ‘LOL Land’

by admin
May 23, 2025
0

In brief Yield Guild Games has launched a new publishing division, YGG Play, focused on casual, crypto-native titles it dubs...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
BTC Enters Strongest Accumulation Phase Since January as Bitcoin Price Tops 0K

BTC Enters Strongest Accumulation Phase Since January as Bitcoin Price Tops $110K

May 23, 2025
Anthropic’s debuts most powerful AI yet amid ‘whistleblowing’ controversy

Anthropic’s debuts most powerful AI yet amid ‘whistleblowing’ controversy

May 23, 2025
Global Darknet Bust Leads to 0M in Digital Asset and Cash Seizures

Global Darknet Bust Leads to $200M in Digital Asset and Cash Seizures

May 23, 2025
US big banks hold early talks on joint crypto stablecoin: WSJ

US big banks hold early talks on joint crypto stablecoin: WSJ

May 23, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com