The Crocodilus malware is spreading globally with new cryptocurrency and banking theft features.

robot
Abstract generation in progress

Trojan Crocodilus, first detected in March 2025 in Turkey, is expanding its attack range to Europe, South America, India, Indonesia, and America. This malware masquerades as a casino application, browser, or banking app to steal login information.

In Poland, Crocodilus uses Facebook ads to spread fake applications, bypassing the restrictions of Android 13+. When installed, it displays a fake log in page for banking apps and cryptocurrency wallets, particularly in Spain.

New features include: editing contacts to facilitate phone scams, collecting seed phrases and private keys from cryptocurrency wallets. The malware is more complexly encrypted to avoid analysis.

Smaller campaigns also target cryptocurrency mining applications and European digital banking.

! Crocodilus malware spreads globally with new banking and crypto theft features

View Original
The content is for reference only, not a solicitation or offer. No investment, tax, or legal advice provided. See Disclaimer for more risks disclosure.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)