The Full Spectrum of News.
Published loading...Updated

Android malware Crocodilus adds fake contacts to spoof trusted callers

  • ThreatFabric researchers reported in late March 2025 that the Crocodilus Android banking trojan now adds fake contacts to victims' phones to spoof trusted callers.
  • Crocodilus spreads via malicious Facebook ads targeting users mainly over age 35 in Europe, South America, Asia, and expanding worldwide.
  • The malware displays fraudulent login overlays, bypasses Android 13 security, and uses contact spoofing labeled as "Bank Support" to trick users into answering scam calls.
  • Each Facebook ad was viewed over 1,000 times but stayed online only 1-2 hours, indicating well-resourced attackers rapidly deploying evasion-focused updates.
  • This evolving tactic could bypass fraud filters and increase data theft risks, suggesting users avoid untrusted downloads and remain cautious of suspicious contacts or calls.
Insights by Ground AI
Does this summary seem wrong?

11 Articles

All
Left
Center
3
Right
Center

Researchers from the Dutch company ThreatFabric reported the expansion of a new three-bank for Android, called Crocodilus.

·Romania
Read Full Article

The person affected is not safe even if they are apparently being called by someone who is in their contact list: the malware called Crocodilus can also add fake contacts to their phone.

A new Android malware is currently causing concern in the security branch: The malware called Crocodilus has been recently further developed and can now create sophisticated contacts on infected smartphones to build on them. (Read more)

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Tuesday, June 3, 2025.
Sources are mostly out of (0)