Cointime

Download App
iOS & Android

Android malware ‘Crocodilus’ can take over phones to steal crypto

Cybersecurity firm Threat Fabric says it has found a new family of mobile-device malware that can launch a fake overlay for certain apps to trick Android users into providing their crypto seed phrases as it takes over the device.

Threat Fabric analysts said in a March 28 report that the Crocodilus malware uses a screen overlay warning users to back up their crypto wallet key by a specific deadline or risk losing access.

“Once a victim provides a password from the application, the overlay will display a message: Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet,” Threat Fabric said. 

“This social engineering trick guides the victim to navigate to their seed phrase wallet key, allowing Crocodilus to harvest the text using its accessibility logger.” 

Once the threat actors have the seed phrase, they can seize complete control of the wallet and “drain it completely.” 

Threat Fabric says despite it being a new malware, Crocodilus has all the features of modern banking malware, with overlay attacks, advanced data harvesting through screen capture of sensitive information such as passwords and remote access to take control of the infected device. 

Initial infection occurs by inadvertently downloading the malware in other software that bypasses Android 13 and security protections, according to Threat Fabric. 

Once installed, Crocodilus requests accessibility service to be enabled, which enables the hackers to gain access to the device. 

“Once granted, the malware connects to the command-and-control (C2) server to receive instructions, including the list of target applications and the overlays to be used,” Threat Fabric said. 

It runs continuously, monitoring app launches and displaying overlays to intercept credentials. When a targeted banking or cryptocurrency app is opened, the fake overlay launches over the top and mutes the sound while the hackers take control of the device.  

“With stolen PII and credentials, threat actors can take full control of a victim’s device using built-in remote access, completing fraudulent transactions without detection,” Threat Fabric said. 

Threat Fabrix’s Mobile Threat Intelligence team has found the malware targets users in Turkey and Spain but said the scope of use will likely broaden over time. 

They also speculated that the developers could speak Turkish, based on the notes in the code, and added that a threat actor known as Sybra or another hacker testing out new software could be behind the malware. 

“The emergence of the Crocodilus mobile banking Trojan marks a significant escalation in the sophistication and threat level posed by modern malware.” 

“With its advanced Device-Takeover capabilities, remote control features, and the deployment of black overlay attacks from its earliest iterations, Crocodilus demonstrates a level of maturity uncommon in newly discovered threats,” Threat Fabric added. 

Comments

All Comments

Recommended for you

  • BTC Falls Below $78,000

    Market data shows that BTC has fallen below $78,000, currently priced at $77,977.99, with a 24-hour increase of 1.9%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Trump States the U.S. Will Not Leave the Strait of Hormuz

    On May 2, U.S. President Trump stated that the United States will currently "not leave" the Strait of Hormuz. He defended the U.S. blockade actions, describing them as "very strong." Trump claimed that the blockade measures are effective and asserted that once the war is over, energy prices will significantly drop. "After this war ends, the prices of oil, gas, and everything will plummet," he said. He also praised the U.S. stock market for reaching historic highs and noted that projects during his administration are being completed "on time" and "on budget." (Jinshi)

  • Trump: Personally Inclined Not to Restart Bombing Operations Against Iran

    On May 2, U.S. President Trump stated that he ultimately has two options regarding Iran: either escalate military action significantly or reach an agreement. 'There are indeed options. Do we want to go in and blow them to smithereens to solve the problem once and for all? Or do we want to try to reach an agreement? Those are the options on the table,' Trump said. He also confirmed that he had just received the latest briefing on military options from the U.S. Central Command the previous night. Trump expressed his personal inclination not to restart bombing operations. 'From a humanitarian standpoint, I prefer not to do that,' he said at the White House. (CNN)

  • Trump: Unsatisfied with Iran's Latest Proposal

    On May 2, U.S. President Trump stated: 'Regarding Iran, I am not satisfied with the latest proposal. We are negotiating over the phone, and I am not sure if we can reach an agreement.' (Jinshi)

  • Benset: The Blockade Will Continue Until Iran Restores Pre-War Freedom of Navigation

    On May 1, U.S. Treasury Secretary Benset posted on the X platform, stating that it is difficult for a mouse in a sewer pipe to know what is happening in the outside world. Here are some 'realistic scenarios' for the Iranian leadership—after all, they are indeed in a dark state of information isolation: 1. The U.S. has complete control over the Strait of Hormuz. 2. There is a shortage of hard currency (i.e., U.S. dollars). 3. Rationing of food and gasoline has been implemented. 4. The entire international community has turned against you. 5. The blockade will continue until freedom of navigation is restored to what it was before February 27.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,016.69, with a 24-hour increase of 2.13%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Crypto Exchange Startup Fun Secures $72 Million in Series A Funding

    Crypto exchange service startup Fun has disclosed that it has completed a $72 million Series A funding round, led by Multicoin Capital and tech venture capital firm SignalFire. Other participants include Infinity Ventures, Pharsalus Capital, and Tinder co-founder Justin Mateen. This funding transaction was completed in January of this year but was only made public recently. Fun declined to disclose the valuation of this funding round.

  • ETH Surpasses $2300

    Market data shows that ETH has surpassed $2300, currently priced at $2300.19, with a 24-hour increase of 1.6%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Tether: Q1 Net Profit Reaches $1.04 Billion, Total Assets Approximately $191.77 Billion

    Tether's Q1 2026 performance report reveals that the company achieved a net profit of approximately $1.04 billion amid a highly volatile global market, with excess reserves rising to a record $8.23 billion. As of March 31, 2026, Tether's total assets were approximately $191.77 billion, with total liabilities around $183.54 billion, of which about $183.44 billion corresponds to issued digital tokens. This results in assets exceeding liabilities by $8.23 billion, while the circulation of USDT remained stable, with total token-related liabilities around $183 billion. In terms of reserve structure, Tether continues to focus on short-duration, highly liquid assets, holding approximately $141 billion in U.S. Treasuries, making it the 17th largest holder of U.S. debt globally. Additionally, its reserves include around $20 billion in physical gold and approximately $7 billion in Bitcoin holdings.

  • Israeli Media: U.S. 'About to Decide' on Resuming Military Action Against Iran

    On May 1, Israeli media reported that the United States is 'possibly about to decide' whether to resume military action against Iran, with Israel intensifying preparations to respond to a potential 'renewed conflict' with Iran. According to Israel's Channel 12, Israeli officials are on 'high alert' and preparing for the possibility that U.S.-Iran negotiations could collapse as early as early next week. The report cites senior officials in the Israeli government stating that the U.S. may increase pressure on Iran regarding the Strait of Hormuz and could launch military strikes against Iran's energy facilities and government infrastructure. (Xinhua)