• CONTACT
  • MARKETCAP
  • BLOG
Crypto NEWS
  • BOOKMARKS
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
    • Contact
    • Privacy Policy
    • Terms and Conditions
    • About CryptoNewsUpdate.com
Reading: Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion
Share

Crypto NEWS

0
Font ResizerAa
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
Search
  • Home
  • Shop
  • Bitcoin
  • Crypto News
  • Altcoin
  • Blockchain
  • Market Trends
  • Legal Docs
    • Contact
    • Privacy Policy
    • Terms and Conditions
    • About CryptoNewsUpdate.com
Have an existing account? Sign In
Follow US
© Crypto NEWS Update. All Rights Reserved.
Crypto NEWS > Blog > Altcoin > Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion
Altcoin

Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion

yangzeph4@gmail.com
Last updated: June 3, 2025 1:25 pm
yangzeph4@gmail.com Published June 3, 2025
Share

Android banking trojan Crocodilus has launched new campaigns targeting crypto users and banking customers across Europe and South America.

First detected in March 2025, early Crocodilus samples were largely limited to Turkey, where the malware posed as online casino apps or spoofed bank apps to steal login credentials.

Recent campaigns show it now hitting targets in Poland, Spain, Argentina, Brazil, Indonesia, India and the US, according to findings from ThreatFabric’s Mobile Threat Intelligence (MTI) team.

A campaign targeting Polish users tapped Facebook Ads to promote fake loyalty apps. Clicking the ad redirected users to malicious sites, delivering a Crocodilus dropper, which bypasses Android 13+ restrictions.

Facebook transparency data revealed that these ads reached thousands of users in just one to two hours, with a focus on audiences over 35.

Crocodilus malware is going global. Source: ThreatFabric

Related: Microsoft takes legal action against infostealer Lumma

Crocodilus targets banking and crypto apps

Once installed, Crocodilus overlays fake login pages on top of legitimate banking and crypto apps. It masqueraded as a browser update in Spain, targeting nearly all major banks.

Beyond geographic expansion, Crocodilus has added new capabilities. One notable upgrade is the ability to modify infected devices’ contact lists, enabling attackers to insert phone numbers labeled as “Bank Support,” which could be used for social engineering attacks.

Another key enhancement is an automated seed phrase collector aimed at cryptocurrency wallets. The Crocodilus malware can now extract seed phrases and private keys with greater precision, feeding attackers pre-processed data for fast account takeovers.

Meanwhile, developers have strengthened Crocodilus’ defenses through deeper obfuscation. The latest variant features packed code, additional XOR encryption and intentionally convoluted logic to resist reverse engineering.

MTI analysts also observed smaller campaigns targeting cryptocurrency mining apps and European digital banks.

“Just like its predecessor, the new variant of Crocodilus pays a lot of attention to cryptocurrency wallet apps,” the report said. “This variant was equipped with an additional parser, helping to extract seed phrases and private keys of specific wallets.”

Source: ThreatFabric

Related: COLDRIVER using new malware to steal from Western targets — Google

Crypto drainers sold as malware

In an April 22 report, crypto forensics and compliance firm AMLBot revealed that crypto drainers, malware designed to steal cryptocurrency, have become easier to access as the ecosystem evolves into a software-as-a-service business model.

The report revealed that malware spreaders can rent a drainer for as little as 100-300 USDt (USDT).

On May 19, it was revealed that Chinese printer manufacturer Procolored had distributed Bitcoin-stealing malware alongside its official drivers.

Magazine: Move to Portugal to become a crypto digital nomad — Everybody else is

You Might Also Like

HBAR Price Dodges Red Tide Upon Australian Stablecoin Launch

Trader Says Dogecoin Competitor Headed to the ‘Gulag’ if Support Level Crumbles, Updates Outlook on Bitcoin and Hyperliquid

Kraken Launches Bitcoin Staking with Babylon Protocol

Crypto restores dignity and agency to those excluded by traditional finance.

PEPE Whale Takes $3.5M Hit After 600B Binance Sell-Off

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion
Next Article Ripple’s flagship stablecoin approved for use in Dubai’s key financial center
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Socials

Subscribe to our newslettern

Get Newest Articles Instantly!

Popular News
North Korea Targets Crypto Jobs With New Malware
Blocktech Brew Join Hands With Qila To Promote Web3 Services Across Industries!
$150M money market funds added to Arbitrum’s RWA ecosystem

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Crypto NEWS

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© Crypto NEWS Update. All Rights Reserved.
Welcome Back!

Sign in to your account

Lost your password?