The Crocodilus malware is spreading globally with new cryptocurrency and banking theft features.

robot
Abstract generation in progress

Trojan Crocodilus, first detected in March 2025 in Turkey, is expanding its attack range to Europe, South America, India, Indonesia, and America. This malware masquerades as a casino application, browser, or banking app to steal login information.

In Poland, Crocodilus uses Facebook ads to spread fake applications, bypassing the restrictions of Android 13+. When installed, it displays a fake log in page for banking apps and cryptocurrency wallets, particularly in Spain.

New features include: editing contacts to facilitate phone scams, collecting seed phrases and private keys from cryptocurrency wallets. The malware is more complexly encrypted to avoid analysis.

Smaller campaigns also target cryptocurrency mining applications and European digital banking.

! Crocodilus malware spreads globally with new banking and crypto theft features

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)