Close Menu
  • Home
  • Daily
  • AI
  • Crypto
  • Bitcoin
  • Stock Market
  • E-game
  • Casino
  • World
  • Affiliate News
  • English
    • Português
    • English
    • Español

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Why investing in growth-stage AI startups is getting riskier and more complicated

June 6, 2025

Elden Ring Nightreign DLC Nightfarer Wish List

June 6, 2025

Arca Dumps Circle Shares After Disappointing IPO Allocation

June 6, 2025
Facebook X (Twitter) Instagram
MetaDaily – Breaking News in Crypto, Markets & Digital Trends
  • Home
  • Daily
  • AI
  • Crypto
  • Bitcoin
  • Stock Market
  • E-game
  • Casino
  • World
  • Affiliate News
  • English
    • Português
    • English
    • Español
MetaDaily – Breaking News in Crypto, Markets & Digital Trends
Home » Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion
Crypto

Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion

adminBy adminJune 3, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Share
Facebook Twitter LinkedIn Pinterest Email


Android banking trojan Crocodilus has launched new campaigns targeting crypto users and banking customers across Europe and South America.

First detected in March 2025, early Crocodilus samples were largely limited to Turkey, where the malware posed as online casino apps or spoofed bank apps to steal login credentials.

However, recent campaigns show the Trojan expanding its reach, now hitting targets in Poland, Spain, Argentina, Brazil, Indonesia, India and the US, according to new findings from ThreatFabric’s Mobile Threat Intelligence (MTI) team.

A campaign targeting Polish users tapped Facebook Ads to promote fake loyalty apps. Clicking the ad redirected users to malicious sites, delivering a Crocodilus dropper, which bypasses Android 13+ restrictions.

Facebook transparency data revealed that these ads reached thousands of users in just one to two hours, with a focus on audiences over 35.

Crocodilus malware is going global. Source: ThreatFabric

Related: Microsoft takes legal action against infostealer Lumma

Crocodilus targets banking and crypto apps

Once installed, Crocodilus overlays fake login pages on top of legitimate banking and crypto apps. It masquerades as a browser update in Spain, targeting nearly all major banks.

Beyond geographic expansion, Crocodilus has added new capabilities. One notable upgrade is the ability to modify infected devices’ contact lists, enabling attackers to insert phone numbers labeled as “Bank Support,” which could be used for social engineering attacks.

Another key enhancement is an automated seed phrase collector aimed at cryptocurrency wallets. The Crocodilus malware can now extract seed phrases and private keys with greater precision, feeding attackers pre-processed data for fast account takeovers.

Meanwhile, developers have strengthened Crocodilus’ defenses through deeper obfuscation. The latest variant features packed code, additional XOR encryption, and intentionally convoluted logic to resist reverse engineering.

MTI analysts also observed smaller campaigns targeting cryptocurrency mining apps and European digital banks amid Crocodilus’ growing focus on crypto.

“Just like its predecessor, the new variant of Crocodilus pays a lot of attention to cryptocurrency wallet apps,” the report said. “This variant was equipped with an additional parser, helping to extract seed phrases and private keys of specific wallets.”

Source: ThreatFabric

Related: COLDRIVER using new malware to steal from Western targets — Google

Crypto drainers sold as malware

In an April 22 report, crypto forensics and compliance firm AMLBot revealed that crypto drainers, malware designed to steal cryptocurrency, have become easier to access as the ecosystem evolves into a software-as-a-service business model.

The report revealed that malware spreaders can rent a drainer for as little as 100 to 300 USDt (USDT).

On May 19, it was revealed that Chinese printer manufacturer Procolored distributed Bitcoin-stealing malware alongside its official drivers. The company reportedly used USB drivers to distribute malware-ridden drivers and uploaded the compromised software to cloud storage for global download.

Magazine: Move to Portugal to become a crypto digital nomad — Everybody else is



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleAnalysis: Drone strikes ahead of Russia-Ukraine peace talks leave Trump’s credibility hanging by a thread
Next Article Why Did the Ant King Use Ice Magic in His Final Battle?
admin
  • Website

Related Posts

Arca Dumps Circle Shares After Disappointing IPO Allocation

June 6, 2025

BTC, ETH, XRP, BNB, SOL, DOGE, ADA, HYPE, SUI, LINK

June 6, 2025

Saylor’s Strategy Upsized Stock Offering to $1B for Bitcoin Purchases

June 6, 2025

Ross Ulbricht’s Bitcoin donor tied to dark market Alphabay

June 6, 2025
Leave A Reply Cancel Reply

Our Picks

Voluptatem aliquam adipisci dolor eaque

April 24, 2025

Funeral of Pope Francis Coincides with King’s Day Celebrations in the Netherlands and Curaçao

April 24, 2025

Curaçao’s Waste-to-Energy Plant Remains Unfeasible Due to High Costs

April 23, 2025

Dutch Ministers: No Immediate Threat from Venezuela to ABC Islands

April 23, 2025
Don't Miss
Affiliate Network News

The Sunday Times List of Best Places to Work in 2025

By adminMay 27, 20250

We’re incredibly proud to share that Awin has once again secured a spot on The…

The Sunday Times List of Best Places to Work in 2025

May 23, 2025

Awin Claims Best Affiliate Network or SaaS of the Year at 2025 Performance Marketing Awards

May 15, 2025

Global ThinkTank 2025: Who, What, Where

May 9, 2025
About Us
About Us

Welcome to MetaDaily.io — Your Daily Pulse on the Digital Frontier.

At MetaDaily.io, we bring you the latest, most relevant, and most exciting news from the world of affiliate networks, cryptocurrency, Bitcoin, egaming, and global markets. Whether you’re an investor, gamer, tech enthusiast, or digital entrepreneur, we provide the insights you need to stay ahead of the curve in this fast-moving digital era.

Our Picks

Crypto.com Sues Nevada Over Block on Sports Event Contracts

June 6, 2025

A New Chapter for the Industry

June 5, 2025

Japan’s House of Representatives Passes Online Casino Ban Bill 2025

June 4, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2025 metadaily. Designed by metadaily.

Type above and press Enter to search. Press Esc to cancel.