A new version of the Android malware Crocodilus has introduced a deceptive feature that adds fake contacts to victims’ devices, allowing attackers to spoof calls from trusted sources.
Originally detected in March 2025 by Threat Fabric researchers, Crocodilus was first seen in limited campaigns in Turkey. It initially relied on basic social engineering tactics, such as fake error messages urging users to back up their cryptocurrency wallet keys.
Now, the malware has gone global. Ongoing monitoring by Threat Fabric reveals that Crocodilus is actively targeting users across all continents. Its latest versions come with significant upgrades, particularly focused on evasion and stealth. These include:
- Code packing in the dropper to avoid detection
- An added XOR encryption layer for the payload
- Advanced code convolution and entanglement to resist reverse engineering
- Local parsing of stolen data before exfiltration to enhance quality
Spoofing Trusted Callers with Fake Contacts
A standout feature in the latest variant is its ability to programmatically create fake contacts on an infected device using the ContentProvider API. When the malware receives a specific command, it adds a contact with a chosen name and number—such as “Bank Support”—to the victim’s contact list.
This means any incoming call from that number will display the spoofed contact name, tricking the victim into believing it’s from a legitimate source like a bank, business, or even a family member. Because these contacts aren’t tied to the user’s Google account, they don’t sync across devices, making the deception harder to detect.
Threat Fabric warns that this significantly increases the attacker’s control and social engineering potential, marking Crocodilus as an increasingly dangerous threat.
To avoid infection, Android users should only download apps from Google Play or reputable sources. Make sure to enable Google Play Protect and limit app installations to only essential ones.
As Crocodilus evolves rapidly and employs advanced social engineering techniques, vigilance and cautious behavior remain the best defense.

















Comments