• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
android trojan crocodilus now active in 8 countries, targeting banks

Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets

You are here: Home / General Cyber Security News / Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets
June 3, 2025

A growing number of malicious campaigns have leveraged a recently discovered Android banking trojan called Crocodilus to target users in Europe and South America.

The malware, according to a new report published by ThreatFabric, has also adopted improved obfuscation techniques to hinder analysis and detection, and includes the ability to create new contacts in the victim’s contacts list.

“Recent activity reveals multiple campaigns now targeting European countries while continuing Turkish campaigns and expanding globally to South America,” the Dutch security company said.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Crocodilus was first publicly documented in March 2025 as targeting Android device users in Spain and Turkey by masquerading as legitimate apps like Google Chrome. The malware comes fitted with capabilities to launch overlay attacks against a list of financial apps retrieved from an external server to harvest credentials.

Cybersecurity

It also abuses accessibility services permissions to capture seed phrases associated with cryptocurrency wallets, which can then be used to drain virtual assets stored in them.

The latest findings from ThreatFabric demonstrate an expansion of the malware’s geographic scope as well as ongoing development with enhancements and new features, indicating that it’s being actively maintained by the operators.

Select campaigns aimed at Poland have been found to leverage bogus ads on Facebook as a distribution vector by mimicking banks and e-commerce platforms. These ads lure victims to download an app to claim supposed bonus points. Users who attempt to download the app are directed to a malicious site that delivers the Crocodilus dropper.

Other attack waves targeting Spanish and Turkish users have disguised themselves as a web browser update and an online casino. Argentina, Brazil, India, Indonesia, and the United States are among the other nations that have been singled out by the malware.

In addition to incorporating various obfuscation techniques to complicate reverse engineering efforts, new variants of Crocodilus have the ability to add a specified contact to the victim’s contact list upon receiving the command “TRU9MMRHBCRO.”

It’s suspected that the feature is designed as a countermeasure to new security protections that Google has introduced in Android that alerts users of possible scams when launching banking apps during a screen-sharing session with an unknown contact.

Cybersecurity

“We believe the intent is to add a phone number under a convincing name such as ‘Bank Support,’ allowing the attacker to call the victim while appearing legitimate. This could also bypass fraud prevention measures that flag unknown numbers,” ThreatFabric said.

Another new feature is an automated seed phrase collector that makes use of a parser to extract seed phrases and private keys of specific cryptocurrency wallets.

“The latest campaigns involving the Crocodilus Android banking Trojan signal a concerning evolution in both the malware’s technical sophistication and its operational scope,” the company said. “Notably, its campaigns are no longer regionally confined; the malware has extended its reach to new geographical areas, underscoring its transition into a truly global threat.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «google chrome to distrust two certificate authorities over compliance and Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues
Next Post: Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization scattered spider: understanding help desk scams and how to defend»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.