{"id":12717,"date":"2025-06-03T15:44:34","date_gmt":"2025-06-03T13:44:34","guid":{"rendered":"https:\/\/wsj-crypto.com\/?p=12717"},"modified":"2025-06-03T15:44:34","modified_gmt":"2025-06-03T13:44:34","slug":"crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion","status":"publish","type":"post","link":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/","title":{"rendered":"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion"},"content":{"rendered":"<p><\/p>\n<div data-v-60373258=\"\">\n<p>The Android banking trojan Crocodilus has initiated new operations aimed at cryptocurrency users and banking clients throughout Europe and South America.<\/p>\n<p>Initially <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/andriod-malware-crocodilus-can-take-over-phones-to-steal-crypto\" title=\"null\">identified in March 2025<\/a>, early samples of Crocodilus were predominantly confined to Turkey, where the malware pretended to be online casino applications or counterfeit banking apps to capture login details.<\/p>\n<p>Recent operations indicate it is now targeting individuals in Poland, Spain, Argentina, Brazil, Indonesia, India, and the US, <a data-ct-non-breakable=\"null\" href=\"https:\/\/www.threatfabric.com\/blogs\/crocodilus-mobile-malware-evolving-fast-going-global\" title=\"null\">according<\/a> to insights from ThreatFabric\u2019s Mobile Threat Intelligence (MTI) team.<\/p>\n<p>A campaign aimed at users in Poland utilized Facebook Ads to advertise fraudulent loyalty applications. Clicking on the ad redirected users to harmful sites that delivered a Crocodilus dropper, circumventing Android 13+ restrictions.<\/p>\n<p>Facebook&#8217;s transparency data indicated that these advertisements reached thousands of users in a mere one to two hours, particularly targeting demographics over 35.<\/p>\n<figure><figcaption style=\"text-align: center;\"><em>Crocodilus malware is expanding its global reach. Source: ThreatFabric<\/em><\/figcaption><\/figure>\n<p><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/microsoft-legal-action-against-infostealer-lumma\" title=\"null\"><em><strong>Microsoft initiates legal proceedings against infostealer Lumma<\/strong><\/em><\/a><\/p>\n<h2>Crocodilus targets banking and crypto applications<\/h2>\n<p>Once installed, Crocodilus overlays fraudulent login forms over authentic banking and cryptocurrency apps. It disguised itself as a browser update in Spain, aiming at nearly all major banks.<\/p>\n<p>Apart from geographic growth, Crocodilus has incorporated new functionalities. A significant upgrade includes the capability to alter the contact lists of compromised devices, allowing attackers to insert phone numbers identified as \u201cBank Support,\u201d potentially facilitating social engineering attacks.<\/p>\n<p>Another notable enhancement is the automated seed phrase collector specifically aimed at cryptocurrency wallets. The <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/explained\/crocodilus-malware-explained-how-it-targets-android-crypto-wallets\" title=\"null\">Crocodilus malware can now retrieve<\/a> seed phrases and private keys with improved accuracy, supplying attackers with pre-processed information for swift account takeovers.<\/p>\n<p>In parallel, developers have fortified Crocodilus\u2019 defenses through enhanced obfuscation. The latest version features compressed code, additional XOR encryption, and deliberately complex logic to deter reverse engineering.<\/p>\n<p>MTI analysts have also spotted smaller campaigns directed at cryptocurrency mining applications and European digital banking institutions.<\/p>\n<p>\u201cSimilar to its predecessor, the new variant of Crocodilus pays substantial attention to cryptocurrency wallet applications,\u201d the report noted. \u201cThis variant was equipped with an extra parser, assisting in the extraction of seed phrases and private keys from specific wallets.\u201d<\/p>\n<figure><img decoding=\"async\" alt=\"\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-06\/019735d5-169d-7a88-86d5-5dbf2b60b1cc\" title=\"\"\/><figcaption style=\"text-align: center;\"><em>Source: ThreatFabric<\/em><\/figcaption><\/figure>\n<p data-ct-non-breakable=\"undefined\"><em><strong>Related: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/coldriver-new-malware-steal-western-targets-google\" title=\"null\"><em><strong>COLDRIVER employs new malware to steal from Western targets \u2014 Google<\/strong><\/em><\/a><\/p>\n<h2>Crypto drainers marketed as malware<\/h2>\n<p>In an April 22 report, the crypto forensics and compliance company AMLBot disclosed that crypto drainers, malware created to pilfer cryptocurrency, have become more accessible as the ecosystem <a href=\"https:\/\/cointelegraph.com\/news\/crypto-drainers-sold-as-malware-at-it-conferences\" rel=\"\" target=\"_self\" title=\"https:\/\/cointelegraph.com\/news\/crypto-drainers-sold-as-malware-at-it-conferences\">transforms into a software-as-a-service model<\/a>.<\/p>\n<p>The report indicated that malware distributors can lease a drainer for as little as 100-300 USDt (<a href=\"https:\/\/cointelegraph.com\/tether-price-index\">USDT<\/a>).<\/p>\n<p>On May 19, it was revealed that the Chinese printer company Procolored had <a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/news\/bitcoin-stealer-malware-found-in-official-printer-drivers\" title=\"null\">distributed Bitcoin-stealing malware<\/a> alongside its official drivers.<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a data-ct-non-breakable=\"null\" href=\"https:\/\/cointelegraph.com\/magazine\/move-portugal-become-crypto-digital-nomad-everybody-else-is\/\" title=\"null\"><em><strong>Relocate to Portugal to become a crypto digital nomad \u2014 Everybody else is<\/strong><\/em><\/a><\/p>\n<p><template data-name=\"subscription_form\" data-type=\"crypto_biz\" data-ct-non-breakable=\"undefined\" label=\"Subscription Form: Crypto Biz Newsletter\"\/><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/crocodilus-android-trojan-targets-crypto-banking-apps?utm_source=rss_feed&#038;utm_medium=rss&#038;utm_campaign=rss_partner_inbound\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Android banking trojan Crocodilus has initiated new operations aimed at cryptocurrency users and banking clients throughout Europe and South America. Initially identified in March 2025, early samples of Crocodilus were predominantly confined to Turkey, where the malware pretended to be online casino applications or counterfeit banking apps to capture login details. Recent operations indicate<\/p>\n","protected":false},"author":3,"featured_media":12718,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[2626],"class_list":["post-12717","post","type-post","status-publish","format-standard","has-post-thumbnail","category-bitcoin","tag-gptreturn-a-list-of-comma-separated-tags-from-this-title-crocodilus-android-trojan-adds-crypto-wallet-heist-tools-in-global-expansion-gpt"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto\" \/>\n<meta property=\"og:description\" content=\"The Android banking trojan Crocodilus has initiated new operations aimed at cryptocurrency users and banking clients throughout Europe and South America. Initially identified in March 2025, early samples of Crocodilus were predominantly confined to Turkey, where the malware pretended to be online casino applications or counterfeit banking apps to capture login details. Recent operations indicate\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/\" \/>\n<meta property=\"og:site_name\" content=\"WSJ-Crypto\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-03T13:44:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"799\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"wsjcrypto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"wsjcrypto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/\",\"url\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/\",\"name\":\"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto\",\"isPartOf\":{\"@id\":\"https:\/\/wsj-crypto.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg\",\"datePublished\":\"2025-06-03T13:44:34+00:00\",\"author\":{\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\"},\"breadcrumb\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage\",\"url\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg\",\"contentUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg\",\"width\":1200,\"height\":799,\"caption\":\"Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wsj-crypto.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wsj-crypto.com\/#website\",\"url\":\"https:\/\/wsj-crypto.com\/\",\"name\":\"WSJ-Crypto\",\"description\":\"Just Another Crypto News Website\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wsj-crypto.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\",\"name\":\"wsjcrypto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"caption\":\"wsjcrypto\"},\"url\":\"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/","og_locale":"it_IT","og_type":"article","og_title":"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto","og_description":"The Android banking trojan Crocodilus has initiated new operations aimed at cryptocurrency users and banking clients throughout Europe and South America. Initially identified in March 2025, early samples of Crocodilus were predominantly confined to Turkey, where the malware pretended to be online casino applications or counterfeit banking apps to capture login details. Recent operations indicate","og_url":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/","og_site_name":"WSJ-Crypto","article_published_time":"2025-06-03T13:44:34+00:00","og_image":[{"width":1200,"height":799,"url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg","type":"image\/jpeg"}],"author":"wsjcrypto","twitter_card":"summary_large_image","twitter_misc":{"Scritto da":"wsjcrypto","Tempo di lettura stimato":"2 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/","url":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/","name":"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion - WSJ-Crypto","isPartOf":{"@id":"https:\/\/wsj-crypto.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage"},"image":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage"},"thumbnailUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg","datePublished":"2025-06-03T13:44:34+00:00","author":{"@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7"},"breadcrumb":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#primaryimage","url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg","contentUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/06\/019735e0-1edd-705c-adca-37337b914412.jpeg","width":1200,"height":799,"caption":"Crocodilus Android Trojan Adds Crypto Wallet Heist Tools in Global Expansion"},{"@type":"BreadcrumbList","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/06\/03\/crocodilus-android-trojan-unleashes-new-crypto-wallet-theft-tactics-in-global-expansion\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wsj-crypto.com\/"},{"@type":"ListItem","position":2,"name":"Crocodilus Android Trojan Unleashes New Crypto Wallet Theft Tactics in Global Expansion"}]},{"@type":"WebSite","@id":"https:\/\/wsj-crypto.com\/#website","url":"https:\/\/wsj-crypto.com\/","name":"WSJ-Crypto","description":"Just Another Crypto News Website","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wsj-crypto.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Person","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7","name":"wsjcrypto","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","caption":"wsjcrypto"},"url":"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/12717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/comments?post=12717"}],"version-history":[{"count":2,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/12717\/revisions"}],"predecessor-version":[{"id":12720,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/12717\/revisions\/12720"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media\/12718"}],"wp:attachment":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media?parent=12717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/categories?post=12717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/tags?post=12717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}