DeepNewz, mobile.
People-sourced. AI-powered. Unbiased News.
Download on the App Store
Screenshot of DeepNewz app showing story detail view.
Mar 31, 06:17 PM
Crocodilus Malware Steals Seed Phrases from Android Crypto Wallets in Spain and Turkey, ThreatFabric Warns
Turkey
Infosec
Hacks
Tech
Crypto
World

Crocodilus Malware Steals Seed Phrases from Android Crypto Wallets in Spain and Turkey, ThreatFabric Warns

Authors
  • CNN TÜRK
  • Cointelegraph
  • Android Police
17

A new Android malware named Crocodilus has been identified by security firm ThreatFabric, targeting cryptocurrency wallets by stealing seed phrases. The malware disguises itself as legitimate crypto-related apps and uses social engineering tactics to trick users into backing up their keys, thereby gaining access to their digital wallets. Crocodilus operates by requesting Android Accessibility permissions, allowing it to bypass security measures and deploy screen overlays to intercept credentials. It has been reported to affect users in Spain and Turkey, with the malware using Turkish debug language. The malware functions as a remote access trojan (RAT), enabling operators to control the device remotely, including the ability to use a black screen overlay to hide their actions. The malware's distribution involves a proprietary dropper that evades Android 13 and later security protections, installing without triggering Google Play Protect. Once installed, it can perform various malicious actions, including remote control of the device, intercepting SMS messages, and capturing Google Authenticator codes for two-factor authentication.

Written with ChatGPT .

Additional media

Image #1 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #2 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #3 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #4 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #5 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #6 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #7 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #8 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433
Image #9 for story crocodilus-malware-steals-seed-phrases-android-crypto-wallets-spain-turkey-warns-0bfbb433