Sunday, 7 September 2025
29.6 C
Singapore
27.1 C
Thailand
19.5 C
Indonesia
27.5 C
Philippines

Android malware adds fake contacts to your phone and drains your bank – here’s how to protect yourself

New Android malware adds fake contacts to scam you over the phone and drain your bank — here’s how to stay protected.

You may want to think twice before answering your phone — especially if it looks like your bank is calling. A dangerous new Android malware called Crocodilus has been making its way worldwide and is now more advanced than ever. Its latest feature? It can add fake contacts to your phone to make scam calls look like they’re from trusted sources.

Crocodilus was first discovered back in March by security experts at Threat Fabric. At the time, it was mainly attacking crypto users in Turkey. But now, it has gone global. The malware targets Android users in the United States, Spain, Argentina, Brazil, Indonesia, and India.

Cybersecurity firm Field Effect warns that Crocodilus uses a custom installer, a dropper, to get around Android’s built-in security. Unlike other malware, it doesn’t need permission from the user or access to Accessibility Services to get onto your device. It can even bypass Google’s Play Protect security feature, making it hard to detect or remove.

This malware is particularly worrying because of its new ability to create fake contact entries. If you visit a dodgy website and unknowingly download the malware, your phone might later show an incoming call from “Your Bank.” But it’s not your bank — a hacker trying to steal your money.

Why this malware is so dangerous

Crocodilus is already packed with dangerous features. It can take full control of your phone, steal personal data, and even overlay fake login pages on top of your real banking apps. This trick is designed to steal your usernames and passwords.

With the new feature, scammers can now make you think that texts or calls are coming from your family, friends, or workplace. Imagine receiving a message from “Mum” asking you to send money urgently — when, in fact, it’s a hacker.

It’s also important to note that these fake contacts won’t appear on your other devices. They don’t sync to your Google account, so if you log in from another phone or computer, you won’t see them. They exist only on the infected phone, making them even more challenging to trace.

Experts don’t know exactly how users are being tricked into downloading the malware. But it’s believed to be spreading through shady websites, fake adverts on social media, scam messages, and untrustworthy app stores.

How to stay protected

Keeping your phone safe from malware like Crocodilus requires a few simple steps. First, try to limit the number of apps on your phone. The fewer apps you have, the easier it is to keep them updated and secure.

Next, only download apps from trusted sources. Stick to the Google Play Store or official stores like Samsung Galaxy Store or the Amazon Appstore. Apps from third-party stores often skip security checks and are more likely to be infected.

Make sure Google Play Protect is turned on. It’s a free tool that checks your apps for malware and alerts you if something’s wrong. But since some threats, like Crocodilus, can sneak past it, it’s also worth installing a reliable antivirus app for Android.

If you want added protection, identity theft protection services can help you recover if a scam has hit you. These services often include support to recover lost funds and repair your credit.

Crocodilus is still new, but it’s already changing quickly and being used in more places. That means it’s likely to grow more dangerous in the coming months. Staying alert, being cautious about what you download, and using good security tools can help you stay ahead of the threats.

Hot this week

Researchers show how 5G phones can be downgraded to 4G in a new cyberattack

Researchers have revealed a toolkit that can downgrade 5G phones to 4G, exposing them to known security flaws and raising concerns about mobile security.

FIFAe partners with Lenovo to power FIFAe Finals 2025 in Riyadh

FIFAe partners with Lenovo to power the FIFAe Finals 2025 in Riyadh, featuring top esports teams competing on Legion gaming devices.

ECOVACS unveils DEEBOT X11 with PowerBoost and expands service robot portfolio at IFA 2025

Ecovacs launches DEEBOT X11 with PowerBoost and expands its service robot lineup with ULTRAMARINE at IFA 2025.

Banks urged to balance opportunities and risks of agentic AI

Moneythor warns that while agentic AI offers exponential potential for banks, the risks are just as significant without safeguards.

Designer reimagines floppy disks as SD card storage cases

Designer Ayushmaan Singh Jodha turns the classic floppy disk into a nostalgic, collectable SD card case with a practical twist.

OpenAI to launch job platform and AI certification scheme

OpenAI will launch an AI job platform and certification scheme to help employers find talent and upskill job seekers.

Meta improves threaded posts on Threads with clearer design

Meta is updating Threads with clearer thread labels, numbered posts, and new layout tools to improve user experience.

US court rules Google can keep Apple deal but must share search data with rivals

A US court ruled Google can keep its Apple deal but must share search data with rivals, marking a key antitrust decision.

ECOVACS unveils DEEBOT X11 with PowerBoost and expands service robot portfolio at IFA 2025

Ecovacs launches DEEBOT X11 with PowerBoost and expands its service robot lineup with ULTRAMARINE at IFA 2025.

Related Articles

Popular Categories