Crocodilus – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 04 Jun 2025 06:44:53 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Crocodilus – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Android Malware Crocodilus Goes Global with Smarter Theft Tools https://earlybirdsinvest.com/android-malware-crocodilus-goes-global-with-smarter-theft-tools/ https://earlybirdsinvest.com/android-malware-crocodilus-goes-global-with-smarter-theft-tools/#respond Wed, 04 Jun 2025 06:44:52 +0000 https://earlybirdsinvest.com/android-malware-crocodilus-goes-global-with-smarter-theft-tools/

The Mobile Threat Intelligence team at ThreatFabric has reported that the Android malware, Crocodilus, is targeting banking and cryptocurrency users in several regions, including Europe, South America, Asia, and the United States.

In Poland, a recent campaign used Facebook ads to promote a fake rewards app. When users clicked the ad, they were redirected to a malicious website that installed malware. This version of Crocodilus could bypass the protections in Android 13 and later versions.

Meanwhile, in Spain, the malware pretended to be a browser update and went after customers of nearly all major banks. Once installed, it overlays fake login pages onto real banking and crypto apps.

Proof of Work vs Proof of Stake: Which is Better? (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Recent updates to Crocodilus include new tools for stealing more than just login details.

One feature enables the malware to add fake phone numbers to a device’s contact list, which labels them as “Bank Support”. Another new tool focuses on cryptocurrency wallets. Crocodilus includes a feature that can automatically collect recovery phrases and private keys.

Furthermore, the developers behind Crocodilus have added new layers of code protection. The malware employs multiple forms of encryption and complex programming techniques, which hinder efforts to understand its operation and mitigate its effects.

Originally found in Turkey in March 2025, Crocodilus disguised itself as fake gambling and banking apps to steal login information.

On May 22, cybersecurity firm Moonlock reported that hackers are targeting macOS users with fake Ledger Live apps. How do these fake apps work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/android-malware-crocodilus-goes-global-with-smarter-theft-tools/feed/ 0 40031
New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/ https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/#respond Mon, 31 Mar 2025 08:29:04 +0000 https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/

A new “highly capable” mobile banking malware dubbed “Crocodilus,” targets Android devices, extorting sensitive crypto wallet credentials using social engineering tactics.

A recent research by cybersecurity firm Threat Fabric found the emergence of a new malware family Crocodilus. The malware is reportedly distributed through a proprietary dropper that bypasses Android 13+ restrictions.

“Despite being new, it already includes all the necessary features of modern banking malware: overlay attacks, keylogging, remote access, and ‘hidden’ remote control capabilities,” analysts noted.

Sophisticated Android malware designed to steal cryptocurrency private keys isn’t new. In October 2024, the FBI issued a warning about a similar malware called SpyAgent, which was linked to North Korean hackers.

However, what differs in the new mobile banking Trojan Crocodilus is the “device takeover and advanced credential theft,” Threat Fabric wrote on X.

Crocodilus Displays Overlays to Target Banks and Cryptos

Crocodilus malware works on a modus operandi similar to modern “Device Takeover banking Trojan,” analysts noted. After initial installation via a proprietary dropper, the malware requests “Accessibility Service” to be enabled, they added.

In order to intercept credentials, Crocodilus connects to the command-and-control (C2) server for instructions such as overlays to be used.

Further, the threat initially appeared in Spain and Turkey, targeting several crypto wallets, the Mobile Threat Intelligence team revealed.

“We expect this scope to broaden globally as the malware evolves,” the team noted.

Additionally, the two-factor authentication (2FA) is bypassed by the malware using RAT command that triggers a screen capture on the content of the Google Authenticator application. Crocodilus captures the code displayed on the screen in the Google Authenticator app, and sends to the C2.

Malware Instructs Victims to Do the Job

Unlike other Trojans, Crocodilus overlays target crypto wallet by asking victims to take a backup of their wallet keys.

“Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet,” the overlay text reads.

This social engineering hack guides victims to navigate to their seed phrase. This inturn allows Crocodilus to extract the text using its Accessibility Logger.

“With this information, attackers can seize full control of the wallet and drain it completely,” Threat Fabric analysts said.

The post New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research appeared first on Cryptonews.

]]>
https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/feed/ 0 28185