Crocodilus malware can steal sensitive crypto wallet credentials

A new Android banking malware called Crocodilus is targeting crypto wallet credentials through advanced social engineering, according to Threat Fabric.

Distributed via a proprietary dropper that evades Android 13+ restrictions, Crocodilus features overlay attacks, keylogging, remote access, and hidden control capabilities.

Unlike previous malware like SpyAgent, Crocodilus excels in device takeover and credential theft.

It tricks users into enabling Accessibility Services, then uses overlays to mimic legitimate apps and steal data, initially targeting banks and crypto wallets in Spain and Turkey, with expected global expansion.

It bypasses two-factor authentication by capturing Google Authenticator codes via screen recording.

Uniquely, it displays fake prompts urging victims to "back up" wallet keys within 12 hours, guiding them to reveal seed phrases, which are logged and sent to a command-and-control server, enabling attackers to drain wallets completely. Show Less

https://cryptonews.com/news/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/
 6

Disclaimer: The content presented on this website, including any analyses, reviews, and ratings, is provided for informational purposes only and should not be considered financial advice. crowd.news does not endorse or recommend any financial transactions or investments based on the information available on this platform. Visitors to this site should perform their own due diligence and consult with a professional financial advisor before making any investment decisions. crowd.news is not liable for any actions taken, financial or otherwise, based on information or links from this website.