By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials
Tech News

New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 29, 2025Ravie LakshmananThreat Intelligence / Mobile Security

Cybersecurity researchers have discovered a new Android banking malware called Crocodilus that’s primarily designed to target users in Spain and Turkey.

“Crocodilus enters the scene not as a simple clone, but as a fully-fledged threat from the outset, equipped with modern techniques such as remote control, black screen overlays, and advanced data harvesting via accessibility logging,” ThreatFabric said.

As with other banking trojans of its kind, the malware is designed to facilitate device takeover (DTO) and ultimately conduct fraudulent transactions. An analysis of the source code and the debug messages reveals that the malware author is Turkish-speaking.

Cybersecurity

The Crocodilus artifacts analyzed by the Dutch mobile security company masquerade as Google Chrome (package name: “quizzical.washbowl.calamity”), which acts as a dropper capable of bypassing Android 13+ restrictions.

Once installed and launched, the app requests permission to Android’s accessibility services, after which contact is established with a remote server to receive further instructions, the list of financial applications to be targeted, and the HTML overlays to be used to steal credentials.

Crocodilus is also capable of targeting cryptocurrency wallets with an overlay that, instead of serving a fake login page to capture login information, shows an alert message urging victims to backup their seed phrases within 12, or else risk losing access to their wallets.

Mobile Security

This social engineering trick is nothing but a ploy on the part of the threat actors to guide the victims to navigate to their seed phrases, which are then harvested through the abuse of the accessibility services, thereby allowing them to gain full control of the wallets and drain the assets.

“It runs continuously, monitoring app launches and displaying overlays to intercept credentials,” ThreatFabric said. “The malware monitors all accessibility events and captures all the elements displayed on the screen.”

This allows the malware to log all activities performed by the victims on the screen, as well as trigger a screen capture of the contents of the Google Authenticator application.

Cybersecurity

Another feature of Crocodilus is its ability to conceal the malicious actions on the device by displaying a black screen overlay, as well as muting sounds, thereby ensuring that they remain unnoticed by the victims.

Some of the important features supported by the malware are listed below –

  • Launch specified application
  • Self-remove from the device
  • Post a push notification
  • Send SMS messages to all/select contacts
  • Retrieve contact lists
  • Get a list of installed applications
  • Get SMS messages
  • Request Device Admin privileges
  • Enable black overlay
  • Update C2 server settings
  • Enable/disable sound
  • Enable/disable keylogging
  • Make itself a default SMS manager

“The emergence of the Crocodilus mobile banking Trojan marks a significant escalation in the sophistication and threat level posed by modern malware,” ThreatFabric said.

“With its advanced Device-Takeover capabilities, remote control features, and the deployment of black overlay attacks from its earliest iterations, Crocodilus demonstrates a level of maturity uncommon in newly discovered threats.”

The development comes as Forcepoint disclosed details of a phishing campaign that has been found employing tax-themed lures to distribute the Grandoreiro banking trojan targeting Windows users in Mexico, Argentina, and Spain by means of an obfuscated Visual Basic script.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

OnePlus 15 is Wake-up Call that Apple & Samsung Should Not Ignore

A Collision With Space Debris Leaves 3 Chinese Astronauts Stranded in Orbit

DoorDash email spoofing vulnerability sparks messy disclosure dispute

Keychain announcing new funding from top UK retailers and launches AI OS for retailers

Google SIMA 2 AI Self-Improvement AI, AGI Progress & Questions

TAGGED: Android, banking Trojan, cryptocurrency, Cyber Security, Cybersecurity, data theft, Internet, mobile security, social engineering, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article As Trump takes aim at election rules, Colorado Democrats view state voting-rights bill as a bulwark
Next Article Bitcoin adoption in EU limited by ‘fragmented’ regulations — Analysts
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Top analyst sees ‘genuine cracks for mid- to lower-end consumers’ as the K-shaped economy continues to bite
Business
Meghan Trainor Then & Now: Photos of the Singer’s Transformation
Celebrity
Indie games just made history at The Game Awards 2025
Gaming News
Resident Evil Requiem Demo Isn’t Currently Planned: “We Just Want to Finish The Game”
Gaming News
Aave introduces mobile savings app with 9% interest and insurance protection
Crypto
Is Saylor’s Bitcoin Strategy A ‘Fraud’? Schiff Wants A Live Debate To Prove It
Crypto
Workers turn to ‘polyworking’ to combat frozen salaries and inflation
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Top analyst sees ‘genuine cracks for mid- to lower-end consumers’ as the K-shaped economy continues to bite

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Top analyst sees ‘genuine cracks for mid- to lower-end consumers’ as the K-shaped economy continues to bite
November 17, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?