Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

The Hacker News by The Hacker News
June 3, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Jun 03, 2025Ravie LakshmananMobile Security / Malware

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America.

The malware, according to a new report published by ThreatFabric, has also adopted improved obfuscation techniques to hinder analysis and detection, and includes the ability to create new contacts in the victim’s contacts list.

“Recent activity reveals multiple campaigns now targeting European countries while continuing Turkish campaigns and expanding globally to South America,” the Dutch security company said.

Crocodilus was first publicly documented in March 2025 as targeting Android device users in Spain and Turkey by masquerading as legitimate apps like Google Chrome. The malware comes fitted with capabilities to launch overlay attacks against a list of financial apps retrieved from an external server to harvest credentials.

Cybersecurity

It also abuses accessibility services permissions to capture seed phrases associated with cryptocurrency wallets, which can then be used to drain virtual assets stored in them.

The latest findings from ThreatFabric demonstrate an expansion of the malware’s geographic scope as well as ongoing development with enhancements and new features, indicating that it’s being actively maintained by the operators.

Select campaigns aimed at Poland have been found to leverage bogus ads on Facebook as a distribution vector by mimicking banks and e-commerce platforms. These ads lure victims to download an app to claim supposed bonus points. Users who attempt to download the app are directed to a malicious site that delivers the Crocodilus dropper.

Other attack waves targeting Spanish and Turkish users have disguised themselves as a web browser update and an online casino. Argentina, Brazil, India, Indonesia, and the United States are among the other nations that have been singled out by the malware.

In addition to incorporating various obfuscation techniques to complicate reverse engineering efforts, new variants of Crocodilus have the ability to add a specified contact to the victim’s contact list upon receiving the command “TRU9MMRHBCRO.”

It’s suspected that the feature is designed as a countermeasure to new security protections that Google has introduced in Android that alerts users of possible scams when launching banking apps during a screen-sharing session with an unknown contact.

Cybersecurity

“We believe the intent is to add a phone number under a convincing name such as ‘Bank Support,’ allowing the attacker to call the victim while appearing legitimate. This could also bypass fraud prevention measures that flag unknown numbers,” ThreatFabric said.

Another new feature is an automated seed phrase collector that makes use of a parser to extract seed phrases and private keys of specific cryptocurrency wallets.

“The latest campaigns involving the Crocodilus Android banking Trojan signal a concerning evolution in both the malware’s technical sophistication and its operational scope,” the company said. “Notably, its campaigns are no longer regionally confined; the malware has extended its reach to new geographical areas, underscoring its transition into a truly global threat.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Turkcell dosahuje globálního prvenství v infrastruktuře 5G

Turkcell dosahuje globálního prvenství v infrastruktuře 5G

Recommended.

LeakSecure™ Rolls Out Major App Upgrade for Smarter Home Water Protection

LeakSecure™ Rolls Out Major App Upgrade for Smarter Home Water Protection

November 20, 2025
The AI race between China and the U.S. heats up. These stocks could be winners, Bernstein says

The AI race between China and the U.S. heats up. These stocks could be winners, Bernstein says

March 22, 2026

Trending.

Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026
2025 Wired, WLAN Gartner Magic Quadrant: Cisco Drops To Challenger, NaaS Specialists Join

2025 Wired, WLAN Gartner Magic Quadrant: Cisco Drops To Challenger, NaaS Specialists Join

July 14, 2025
CTIA Names Preston Wise Senior Vice President of External and State Affairs

CTIA Names Preston Wise Senior Vice President of External and State Affairs

May 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio