logo

Android malware Crocodilus adds fake contacts to spoof trusted callers

ID: 1571e3ab-0b55-5d69-82ec-c6196abf3785

STIX ID: report--1571e3ab-0b55-5d69-82ec-c6196abf3785

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-06-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report details the evolution of the Crocodilus Android malware: researchers observed global expansion and multiple evasion/sophistication improvements (dropper packing, additional XOR payload encryption, code convolution, and local parsing of stolen data). A notable new TTP programmatically adds fake local contacts on infected devices to enable believable social-engineering calls (e.g., posing as bank support), increasing the malware's effectiveness in stealing credentials and controlling devices; users are advised to download apps only from trusted sources and keep protections like Play Protect enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.