By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials
Tech News

New Android Trojan Crocodilus Abuses Accessibility to Steal Banking and Crypto Credentials

By Viral Trending Content 4 Min Read
Share
SHARE

Mar 29, 2025Ravie LakshmananThreat Intelligence / Mobile Security

Cybersecurity researchers have discovered a new Android banking malware called Crocodilus that’s primarily designed to target users in Spain and Turkey.

“Crocodilus enters the scene not as a simple clone, but as a fully-fledged threat from the outset, equipped with modern techniques such as remote control, black screen overlays, and advanced data harvesting via accessibility logging,” ThreatFabric said.

As with other banking trojans of its kind, the malware is designed to facilitate device takeover (DTO) and ultimately conduct fraudulent transactions. An analysis of the source code and the debug messages reveals that the malware author is Turkish-speaking.

Cybersecurity

The Crocodilus artifacts analyzed by the Dutch mobile security company masquerade as Google Chrome (package name: “quizzical.washbowl.calamity”), which acts as a dropper capable of bypassing Android 13+ restrictions.

Once installed and launched, the app requests permission to Android’s accessibility services, after which contact is established with a remote server to receive further instructions, the list of financial applications to be targeted, and the HTML overlays to be used to steal credentials.

Crocodilus is also capable of targeting cryptocurrency wallets with an overlay that, instead of serving a fake login page to capture login information, shows an alert message urging victims to backup their seed phrases within 12, or else risk losing access to their wallets.

Mobile Security

This social engineering trick is nothing but a ploy on the part of the threat actors to guide the victims to navigate to their seed phrases, which are then harvested through the abuse of the accessibility services, thereby allowing them to gain full control of the wallets and drain the assets.

“It runs continuously, monitoring app launches and displaying overlays to intercept credentials,” ThreatFabric said. “The malware monitors all accessibility events and captures all the elements displayed on the screen.”

This allows the malware to log all activities performed by the victims on the screen, as well as trigger a screen capture of the contents of the Google Authenticator application.

Cybersecurity

Another feature of Crocodilus is its ability to conceal the malicious actions on the device by displaying a black screen overlay, as well as muting sounds, thereby ensuring that they remain unnoticed by the victims.

Some of the important features supported by the malware are listed below –

  • Launch specified application
  • Self-remove from the device
  • Post a push notification
  • Send SMS messages to all/select contacts
  • Retrieve contact lists
  • Get a list of installed applications
  • Get SMS messages
  • Request Device Admin privileges
  • Enable black overlay
  • Update C2 server settings
  • Enable/disable sound
  • Enable/disable keylogging
  • Make itself a default SMS manager

“The emergence of the Crocodilus mobile banking Trojan marks a significant escalation in the sophistication and threat level posed by modern malware,” ThreatFabric said.

“With its advanced Device-Takeover capabilities, remote control features, and the deployment of black overlay attacks from its earliest iterations, Crocodilus demonstrates a level of maturity uncommon in newly discovered threats.”

The development comes as Forcepoint disclosed details of a phishing campaign that has been found employing tax-themed lures to distribute the Grandoreiro banking trojan targeting Windows users in Mexico, Argentina, and Spain by means of an obfuscated Visual Basic script.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Android, banking Trojan, cryptocurrency, Cyber Security, Cybersecurity, data theft, Internet, mobile security, social engineering, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article As Trump takes aim at election rules, Colorado Democrats view state voting-rights bill as a bulwark
Next Article Bitcoin adoption in EU limited by ‘fragmented’ regulations — Analysts
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?