logo

Android Under Attack: Crocodilus Trojan Captures OTPs from Google Authenticator

ID: 65c20fbc-d211-5fc1-bc46-8d032df8921a

STIX ID: report--65c20fbc-d211-5fc1-bc46-8d032df8921a

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: do son

...
...

ThreatFabric’s report describes a newly identified Android banking Trojan called Crocodilus that uses a proprietary dropper to bypass Android 13+ protections, requests Accessibility permissions, deploys overlay attacks and an Accessibility-based logger to capture credentials and seed phrases, can harvest OTPs (including Google Authenticator codes) via screen enumeration, and provides hidden remote control (black-screen overlays, muted audio) to fully take over devices and drain banking and cryptocurrency assets; indicators suggest Turkish-speaking developer(s) and potential ties to the actor ‘sybra’.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.