New Crocodilus malicious software steals Android users crypto wallet keys

2025-03-31 01:16:52
On March 31st, researchers under the security company ThreatFabric said that the new malicious software Crocodilus can steal the wallet mnemonic of Android users. The malicious software spreads through proprietary drivers and bypasses the security protection of Android 13 (and later). When users install malicious software, it will not trigger Play Protect.
The malicious software used a screen overlay to falsely warn users to "backup wallet mnemonic in settings within 12 hours" or risk losing access to the wallet.