• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Analysis

Crocodilus Malware Has Been Draining Crypto Wallets on Android

admin by admin
April 25, 2025
in Analysis
0
Crocodilus Malware Has Been Draining Crypto Wallets on Android
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Android users beware: A newly discovered piece of malware is targeting smartphone crypto wallets.

Uncovered by fraud prevention firm ThreatFabric, the “Crocodilus” mobile banking trojan employs tools including remote control, black screen overlays, and advanced data harvesting through accessibility logging to trick crypto holders into handing over their wallet seed phrase.

Related articles

Ledger Launches Solana Branded Ledger Flex Hardware Wallets

Ledger Launches Solana Branded Ledger Flex Hardware Wallets

May 22, 2025
Sui Token Starts to Recover After 3 Million Exploit on Its Biggest Decentralized Exchange

Sui Token Starts to Recover After $223 Million Exploit on Its Biggest Decentralized Exchange

May 22, 2025

The malware “is masquerading as crypto-related apps and involves specific social engineering techniques to make victims reveal the secrets stored inside cryptocurrency wallet applications,” Aleksandar Eremin, head of mobile threat intelligence at ThreatFabric, told Decrypt. He added that it’s pointing to the “specific interest of the actors behind it in targeting users of cryptocurrency wallets.”

Crucially, this threat tricks Android users into providing the seed phrase for their own cryptocurrency wallet. It does this by issuing a warning that asks users to back up their key to avoid losing access.

ThreatFabric said Crocodilus is being distributed through a proprietary dropper that bypasses security protections on Android 13 or later.

Once this dropper installs the malware, without triggering Play Protect, it requests Accessibility Service permissions. That allows it to bypass the Accessibility Service restrictions, enabling it to deploy a screen overlay to gain passwords.

The malware shows users a fake warning message that reads: “Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet.”

Crocodilus also works as a remote access trojan (RAT), meaning operators can navigate the user interface, swipe using gesture control and even take screenshots. According to ThreatFabric, this allows the malware operator to use Google Authenticator to access two-factor authentication passcodes.

The malware does all this discreetly by using a black screen overlay, so the phone owner can’t actually see what actions are being carried out remotely.

Who is Crocodilus targeting?

At time of publishing it appears that only users in Spain and Turkey have been affected by Crocodilus. The malware was first discovered targeting people in Turkey and Spain, and uses debug language that appears to be in Turkish.

How that initial dropper is downloaded is less clear, according to ThreatFabric, so it could well spread beyond these locations.

According to ThreatFabric, users are tricked into downloading the droppers through malicious sites, social media, fake promotions, text messages and third-party app stores. Android users can mitigate against the risk by only using the Google Play Store to download apps, and not downloading APKs from other sites.

Eremin told Decrypt that despite being a “newcomer to the mobile threat landscape,” Crocodilus’ “rich set of capabilities” could make it a competitor to established malware-as-a-service on underground markets.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



#Crocodilus #Malware #Draining #Crypto #Wallets #Android

Tags: 400 hot versus cold wallets400 the token launch receiveda m et bitcoinaccess to your walletAndroidbagged 6 556 btc for 555been draining crypto walletsCrocodiluscryptocrypto holders incrypto walletdogecoin dogeDraininggenerating btc on btc yield strongindex at 23 100 on aprilindian city of kolkata said kashmirmalwaremanagement aum continued to decline droppingmunich with five games remaining pmunicipal treasury according to statements sharedpaused historic rally stocks cryptoplatform will continue operations led byproposals as unacceptable with littlerise but most peoplethat bitcoin s weak performance reflectsthe secrets stored inside cryptocurrencyuntold numbers of us companies theyusers of cryptocurrencyWallets
Share76Tweet47

Related Posts

Ledger Launches Solana Branded Ledger Flex Hardware Wallets

Ledger Launches Solana Branded Ledger Flex Hardware Wallets

by admin
May 22, 2025
0

In brief The new Ledger Flex Solana Edition offers the same technical features as the standard version but comes in...

Sui Token Starts to Recover After 3 Million Exploit on Its Biggest Decentralized Exchange

Sui Token Starts to Recover After $223 Million Exploit on Its Biggest Decentralized Exchange

by admin
May 22, 2025
0

In brief SUI retraced a small portion of its losses, a few hours after rnews broke that more than $200...

Russia Could Relocate Bitcoin Miners To Northern Regions: Report

Russia Could Relocate Bitcoin Miners To Northern Regions: Report

by admin
May 22, 2025
0

The Russian Ministry of Energy is considering offering its now strictly regulated Bitcoin mining industry incentives to move to the...

Kraken to Offer Tokenized Stock Trading on Solana to Overseas Customers

Kraken to Offer Tokenized Stock Trading on Solana to Overseas Customers

by admin
May 22, 2025
0

In brief Kraken will offer so-called xStocks to overseas customers on Solana. The initiative is being facilitated through a partnership...

Glider is Creating a ‘New Paradigm’ for Automated Crypto Portfolio Management

Glider is Creating a ‘New Paradigm’ for Automated Crypto Portfolio Management

by admin
May 22, 2025
0

In brief Glider is an automated, non-custodial crypto portfolio management platform. The project is the winner of the Start the...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
Ledger Launches Solana Branded Ledger Flex Hardware Wallets

Ledger Launches Solana Branded Ledger Flex Hardware Wallets

May 22, 2025
Nvidia (NVDA), Apple (AAPL), Tesla (TSLA) Among Tokenized Stocks Coming to Crypto Exchange Kraken

Nvidia (NVDA), Apple (AAPL), Tesla (TSLA) Among Tokenized Stocks Coming to Crypto Exchange Kraken

May 22, 2025
Sui Token Starts to Recover After 3 Million Exploit on Its Biggest Decentralized Exchange

Sui Token Starts to Recover After $223 Million Exploit on Its Biggest Decentralized Exchange

May 22, 2025
Kraken to launch 24/7 trading for tokenized US stocks via Solana

Kraken to launch 24/7 trading for tokenized US stocks via Solana

May 22, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com