<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>ThreatFabric Archives - Coin Engineer</title>
	<atom:link href="https://coinengineer.net/blog/tag/threatfabric/feed/" rel="self" type="application/rss+xml" />
	<link>https://coinengineer.net/blog/tag/threatfabric/</link>
	<description>Btc, Coins, Pre-Sale, DeFi, NFT</description>
	<lastBuildDate>Tue, 03 Jun 2025 13:21:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://coinengineer.net/blog/wp-content/uploads/2024/04/cropped-Coin-Engineer-Logo-Favicon-2-32x32.png</url>
	<title>ThreatFabric Archives - Coin Engineer</title>
	<link>https://coinengineer.net/blog/tag/threatfabric/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Crocodilus Malware Expands to Crypto Wallets</title>
		<link>https://coinengineer.net/blog/crocodilus-malware-expands-to-crypto-wallets/</link>
					<comments>https://coinengineer.net/blog/crocodilus-malware-expands-to-crypto-wallets/#respond</comments>
		
		<dc:creator><![CDATA[Yigit Taha OZTURK]]></dc:creator>
		<pubDate>Tue, 03 Jun 2025 17:00:43 +0000</pubDate>
				<category><![CDATA[Crypto News]]></category>
		<category><![CDATA[EN]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[amlbot]]></category>
		<category><![CDATA[Android 13]]></category>
		<category><![CDATA[Android Trojan]]></category>
		<category><![CDATA[banking malware]]></category>
		<category><![CDATA[Crocodilus]]></category>
		<category><![CDATA[crypto drainers]]></category>
		<category><![CDATA[crypto security]]></category>
		<category><![CDATA[Crypto Wallets]]></category>
		<category><![CDATA[Facebook ad scam]]></category>
		<category><![CDATA[malware campaign]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[mobile threat]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[private keys]]></category>
		<category><![CDATA[seed phrase]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[South America]]></category>
		<category><![CDATA[Spain]]></category>
		<category><![CDATA[ThreatFabric]]></category>
		<guid isPermaLink="false">https://coinengineer.net/blog/?p=43731</guid>

					<description><![CDATA[<p>Malicious mobile software continues to evolve—sometimes faster than defenses. One recent threat, Crocodilus, has shifted its focus beyond banking apps to now infiltrate cryptocurrency wallets across multiple continents. First seen in Turkey in March 2025, Crocodilus is now active in countries like Poland, Spain, Brazil, Argentina, India, Indonesia, and the U.S., signaling a global expansion</p>
<p>The post <a href="https://coinengineer.net/blog/crocodilus-malware-expands-to-crypto-wallets/">Crocodilus Malware Expands to Crypto Wallets</a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p data-start="2835" data-end="3062">Malicious mobile software continues to evolve—sometimes faster than defenses. One recent threat, <strong data-start="2932" data-end="2946">Crocodilus</strong>, has shifted its focus beyond banking apps to now infiltrate cryptocurrency wallets across multiple continents.</p>
<p data-start="3064" data-end="3288">First seen in Turkey in March 2025, <strong>Crocodilus</strong> is now active in countries like Poland, Spain, Brazil, Argentina, India, Indonesia, and the U.S., signaling a global expansion that concerns both banks and crypto holders alike.</p>
<h2 data-start="3295" data-end="3325">Fake Apps, Real Intrusions</h2>
<p data-start="3327" data-end="3599">In Poland, attackers used <strong data-start="3353" data-end="3369">Facebook </strong>ads to lure users with bogus loyalty app promotions. These ads—targeted at users over 35—redirected victims to malware-hosting sites. Once installed, the Trojan bypassed <strong data-start="3536" data-end="3550">Android 13</strong> restrictions and deployed its attack mechanisms.</p>
<hr />
<p data-start="3601" data-end="3889"><em>You Might Be Interested In: <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://coinengineer.net/blog/elon-musk-talks-about-the-name-of-a-new-memecoin/">Elon Musk Talks About the Name of a New Memecoin!</a></span></em></p>
<hr />
<p data-start="3601" data-end="3889">In Spain, <strong>Crocodilus</strong> disguised itself as a browser update. Once on a device, it overlays fake login pages on top of real banking and crypto apps, harvesting sensitive credentials. It even inserts fake “Bank Support” contacts into user phonebooks to aid social engineering efforts.</p>
<p data-start="3601" data-end="3889"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-157595 " src="https://coinmuhendisi.com/blog/wp-content/uploads/2025/06/crocodilus-1024x575.png" alt="crocodilus" width="814" height="457" /></p>
<h2 data-start="3896" data-end="3934">Crypto Wallets Under Direct Attack</h2>
<p data-start="3936" data-end="4182">The most alarming upgrade is <strong>Crocodilus</strong>’ new ability to automatically extract seed phrases and private keys from infected devices. Equipped with advanced parsing modules, the malware can quickly hijack wallet access with remarkable precision.</p>
<p data-start="4184" data-end="4371">To avoid detection, the latest variant uses deep obfuscation techniques like XOR encryption and intentionally complex logic, making reverse engineering a challenge for security teams.</p>
<p data-start="4373" data-end="4529">Smaller campaigns have also been seen targeting crypto mining apps and digital banks in Europe—highlighting the malware&#8217;s growing focus on crypto users.</p>
<hr />
<p data-start="4373" data-end="4529"><em>You can also freely share your thoughts and comments about the topic in the comment section. Additionally, don’t forget to follow us on our <span style="color: #0000ff;"><a href="https://t.me/coinengineernews">Telegram</a><span style="color: #000000;">,</span> <a style="color: #0000ff;" href="https://www.youtube.com/@CoinEngineer" target="_blank" rel="noreferrer noopener nofollow">YouTube</a></span><span style="color: #000000;">,</span> and <a href="https://twitter.com/coinengineers" target="_blank" rel="nofollow noopener"><span style="color: #0000ff;">Twitter</span></a> channels for the latest<span style="color: #0000ff;"> <a style="color: #0000ff;" title="News" href="https://coinengineer.net/blog/news/" data-internallinksmanager029f6b8e52c="7">news</a></span> and updates.</em></p>
<p>The post <a href="https://coinengineer.net/blog/crocodilus-malware-expands-to-crypto-wallets/">Crocodilus Malware Expands to Crypto Wallets</a> appeared first on <a href="https://coinengineer.net/blog">Coin Engineer</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coinengineer.net/blog/crocodilus-malware-expands-to-crypto-wallets/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url='https://coinengineer.net/blog/wp-content/uploads/2025/05/taslak-ce-2025-05-17T000247.642.png' type='image/webp' medium='image' width='1920' height='1080'><media:title type='plain'> <![CDATA[USA]]></media:title><media:thumbnail url='https://coinengineer.net/blog/wp-content/uploads/2025/05/taslak-ce-2025-05-17T000247.642.png' width='58' height='33' /></media:content>	</item>
	</channel>
</rss>
