The malware Crocodilus is proliferating around the world with a new feature of crypto wallet and bank hijacking
PANews reported on June 3 that, according to Cointelegraph, the Android banking Trojan Crocodilus has recently upgraded and began to attack cryptocurrency users and bank customers around the world. Security firm ThreatFabric found that the malware had spread from its original Turkish region to Poland, Spain, Argentina and other countries. The latest variant is capable of spreading malicious programs disguised as browser updates through Facebook ads, using overlay attacks to steal login credentials from banks and encrypted apps. The Trojan adds the ability to automatically extract the mnemonic phrase and private key of a cryptocurrency wallet, as well as modify the victim's address book to implant a fake "bank support" number. Attackers can now rent crypto stealing tools to commit crimes for 100-300 USDT per visit. Security experts are warning users to be wary of app updates and ad links from unknown sources.