Android malware Crocodilus adds fake contacts to spoof trusted callers
ID: 1571e3ab-0b55-5d69-82ec-c6196abf3785
STIX ID: report--1571e3ab-0b55-5d69-82ec-c6196abf3785
Feed Name: Bleeping Computer
The report details the evolution of the Crocodilus Android malware: researchers observed global expansion and multiple evasion/sophistication improvements (dropper packing, additional XOR payload encryption, code convolution, and local parsing of stolen data). A notable new TTP programmatically adds fake local contacts on infected devices to enable believable social-engineering calls (e.g., posing as bank support), increasing the malware's effectiveness in stealing credentials and controlling devices; users are advised to download apps only from trusted sources and keep protections like Play Protect enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
