New Crocodilus malware steals Android users’ crypto wallet keys
ID: 5d8bfc51-248c-599f-8181-354a66e68e2f
STIX ID: report--5d8bfc51-248c-599f-8181-354a66e68e2f
Feed Name: Bleeping Computer
Threat Score
Crocodilus is a newly discovered Android banking/infostealer that uses a proprietary dropper to bypass Android 13 protections and Play Protect, abuses Accessibility Service and screen overlays to trick users into revealing cryptocurrency wallet seed phrases and credentials, and provides RAT capabilities enabling full device takeover; initial operations were observed in Turkey and Spain, and researchers advise avoiding side‑loading APKs and keeping Play Protect enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
