logo

New Crocodilus malware steals Android users’ crypto wallet keys

ID: 5d8bfc51-248c-599f-8181-354a66e68e2f

STIX ID: report--5d8bfc51-248c-599f-8181-354a66e68e2f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Crocodilus is a newly discovered Android banking/infostealer that uses a proprietary dropper to bypass Android 13 protections and Play Protect, abuses Accessibility Service and screen overlays to trick users into revealing cryptocurrency wallet seed phrases and credentials, and provides RAT capabilities enabling full device takeover; initial operations were observed in Turkey and Spain, and researchers advise avoiding side‑loading APKs and keeping Play Protect enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.