Technology
Android malware poses as fake contacts to steal your personal data

NEWYou can now listen to Fox News articles!
Hacking keeps evolving, just like any other profession. Cybercriminals are always upgrading their tools, especially malware, to find new ways to scam people and steal data or money. The old tricks no longer work as well. Basic phishing rarely fools anyone twice, so hackers constantly look for new ways to break in.
They rely on whatever grabs your attention and doesn’t raise suspicion, things like social media ads, fake banking apps or updates that look completely normal. One of the fastest-growing threats in this space is Crocodilus.
First detected in early 2025, this Android banking Trojan takes over your contact list to make its scams look more legitimate and harder to spot.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join.
Android phone (Kurt “CyberGuy” Knutsson)
Crocodilus malware: What Android users must know now
The Crocodilus malware was first documented by ThreatFabric cybersecurity researchers in late March 2025. They highlighted its extensive data theft and remote control capabilities.
Crocodilus uses Facebook to infect devices. It appears in ads that look normal, but once clicked, the malware installs itself on your device. In some cases, it mimicked banking and e-commerce apps in Poland, promising users free points in exchange for downloading an app. The link led to a fake site that delivered the malware. Although the ad was only live for a few hours, it still reached thousands of users, most of whom were over 35, a group more likely to have money in the bank.
Smaller but growing campaigns have also been reported in the United States, where Crocodilus disguised itself as crypto wallet tools, mining apps and financial services. These fake apps are often distributed through social media ads or phishing links, targeting Android users who are less likely to question a “legit-looking” financial app. While not yet widespread, the presence of Crocodilus in the U.S. underscores its global reach and rapidly evolving tactics.
ANDROID SECURITY UPGRADES OUTSMART SCAMS AND PROTECT YOUR PRIVACY
The Trojan has also been spotted in Spain, where it disguised itself as a browser update, targeting nearly every major Spanish bank. In Turkey, it posed as an online casino app. And the threat doesn’t stop there.
One of the biggest concerns with Crocodilus is its ability to add fake contacts to your phone, inserting entries like “Bank Support” into your contact list. So, if an attacker calls pretending to be from your bank, your phone may not flag it because it appears to be a trusted number, making social engineering scams much more convincing.
The latest version also includes a more advanced seed phrase collector, especially dangerous for cryptocurrency users. Crocodilus monitors your screen and uses pattern matching to detect and extract sensitive data, such as private keys or recovery phrases, all before quietly sending it to the attacker.

Illustration of a hacker at work (Kurt “CyberGuy” Knutsson)
MASSIVE DATA BREACH EXPOSES 184 MILLION PASSWORDS AND LOGINS
How Crocodilus signals the future of mobile malware threats
Crocodilus shows us what the next wave of mobile threats might look like. It uses real ads to get into your phone. It blends into your digital life in ways that feel familiar. It does not need flashy tricks to succeed. It just needs to appear trustworthy.
This kind of malware is designed for scale. It targets large groups, works across different regions and updates fast. It can pretend to be a bank, a shopping app or even something harmless like a browser update. The scary part is how normal it all looks. People are not expecting something this malicious to hide inside something that looks like a gift.
The creators of Crocodilus understand how people think and act online. They are using that knowledge to build tools that work quietly and effectively. And they are not working alone. This kind of operation likely involves a network of developers, advertisers and distributors all working together.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

A woman working on her laptop with her phone nearby (Kurt “CyberGuy” Knutsson)
HR FIRM CONFIRMS 4M RECORDS EXPOSED IN MAJOR HACK
7 expert tips to protect your Android from Crocodilus malware
1. Avoid downloading apps from ads or unknown sources: Crocodilus often spreads through ads on social media platforms like Facebook. These ads promote apps that look like banking tools, e-commerce platforms or even crypto wallets. If you click and install one, you might be unknowingly downloading malware. Always search for apps directly on trusted platforms like the Google Play Store. Do not install anything from random links, especially those shared through ads, messages or unfamiliar websites.
2. Avoid suspicious links and install strong antivirus protection: Crocodilus spreads through deceptive ads and fake app links. These can look like legitimate banking tools, crypto apps or browser updates. Clicking on them may quietly install malware that hijacks your contacts, monitors your screen or steals login credentials. To stay safe, avoid clicking on links from unknown sources, especially those that promise rewards or warn of urgent problems. Installing strong antivirus software on your Android device adds another layer of protection. It can scan downloads, block malicious behavior and warn you about phishing attempts before they become a bigger issue. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
3. Review app permissions carefully before and after installation: Before you install an app, take a moment to look at the permissions it asks for. If a shopping app wants access to your contacts, messages or screen, that is a red flag. After installing, go to your phone settings and double-check what permissions the app actually has. Malware like Crocodilus relies on overreaching permissions to steal data and gain control. If anything seems unnecessary, revoke the access or uninstall the app entirely.
4. Keep your Android device updated at all times: Security patches are released regularly to block known vulnerabilities. Crocodilus is designed to take advantage of outdated systems and bypass newer Android restrictions. By updating your phone and apps regularly, you reduce the chances of malware slipping through. Set your device to install updates automatically when possible and check manually every so often if you are not sure.
5. Consider using a data removal or monitoring service: While not a direct defense against malware, data removal services can help minimize the damage if your information has already been leaked or sold. These services monitor your personal data on the dark web and offer guidance if your credentials have been compromised. In a case like Crocodilus, where malware may harvest and transmit banking info or crypto keys, knowing your data exposure early can help you act before scammers do. Check out my top picks for data removal services here.
Get a free scan to find out if your personal information is already out on the web
6. Turn on Google Play Protect: Google Play Protect is a built-in security feature on Android phones that scans your apps for anything suspicious. To stay protected, make sure it’s turned on. You can check this by opening the Play Store, tapping your profile icon and selecting Play Protect. From there, you can see if it’s active and run a manual scan of all your installed apps. While it may not catch everything, especially threats from outside the Play Store, it’s still an important first layer of defense against harmful apps like Crocodilus.
7. Be skeptical of unfamiliar contacts or urgent messages: One of the newer tricks Crocodilus uses is modifying your contact list. It can add fake entries that look like customer service numbers or bank helplines. So, if you receive a call from “Bank Support,” it might not be real. Always verify phone numbers through official websites or documents. The same applies to messages asking for personal details or urgent logins. When in doubt, do not respond or click any links. Contact your bank or service provider directly.
DON’T CLICK THAT LINK! HOW TO SPOT AND PREVENT PHISHING ATTACKS IN YOUR INBOX
Kurt’s key takeaway
Crocodilus is one of the most advanced Android banking Trojans seen so far. It spreads through social media ads, hides inside apps that look real and collects sensitive data like banking passwords and crypto seed phrases. It can also add fake contacts to your phone to trick you during scam calls. If you use Android, avoid downloading apps from links in ads or messages. Only install apps from trusted sources like the Google Play Store. Keep your phone updated, and be careful if something looks too good to be true because it probably is.
Who should be held accountable when malware like Crocodilus spreads through platforms like Facebook? Let us know by writing to us at Cyberguy.com/Contact.
For more of my tech tips anbd security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.

Technology
Solar-powered robot zaps weeds without chemicals

NEWYou can now listen to Fox News articles!
Out in the California sun, a new kind of farmhand is hard at work. Powered by solar energy and guided by artificial intelligence, the solar-powered weeding robot for cotton fields is offering farmers a smarter and more sustainable way to tackle weeds.
This technology is arriving just in time, as growers across the country face a shortage of available workers and weeds that are becoming increasingly resistant to herbicides.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
JOB-KILLING ROBOT LEARNS AT WORK, AND IT’S COMING TO THE FACTORY FLOOR
Solar-powered Element robot (Aigen)
Why farmers need alternatives to herbicides and manual labor
Farmers everywhere are facing a tough reality. There simply aren’t enough people willing to do the backbreaking work of weeding fields, and the weeds themselves are getting harder to kill with chemicals. Many farmers would rather avoid using herbicides, but until now, they haven’t had a practical alternative. Kenny Lee, CEO of Aigen, puts it plainly: farmers don’t love chemicals, but they use them because it’s often the only tool available. Aigen’s mission is to give them a better choice.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
How Aigen’s solar-powered weeding robot uses AI to fight weeds
Aigen’s Element robot is designed to meet the real-world needs of modern agriculture. It runs entirely on solar power, which means farmers can save money on fuel while also reducing their environmental impact. The robot uses advanced AI and onboard cameras to spot and remove weeds with impressive accuracy, all without damaging the crops. Its rugged design allows it to handle rough terrain and changing weather, and it can work alongside other robots, communicating wirelessly to cover large fields efficiently. The Element robot isn’t limited to cotton; it’s also being used in soy and sugar beet fields, showing just how versatile this technology can be.

Solar-powered Element robot (Aigen)
Real-world results: Aigen’s robot at work on California cotton farms
At Bowles Farm in California’s Central Valley, Element robots are already proving their worth. These robots are keeping cotton fields weed-free without the need for chemicals, freeing up workers to focus on more skilled tasks and helping farmers manage their operations more efficiently. The technology is not just a promise for the future. It’s delivering real results today.
Top benefits of solar-powered weeding robots for sustainable farming
Switching to solar-powered, AI-driven robots brings a host of benefits. Farmers no longer need to rely on herbicides, which leads to cleaner crops and healthier soil. Labor costs can drop since workers can shift from manual weeding to supervising and maintaining the robots. The robots also collect valuable data on crop health, pests and diseases, giving farmers better information to make decisions. And because the robots run on solar power, farms can reduce their carbon footprint while saving money on energy.

Solar-powered Element robots (Aigen)
Kurt’s key takeaways
Aigen’s Element robot goes beyond being just another cool piece of technology. It really shows what can happen when farming and innovation come together. As more growers start using solar-powered robots like this, chemical-free fields are moving from wishful thinking to something we can actually achieve.
Would you feel comfortable trusting a robot to handle important tasks and help shape the future of how we grow our food? Let us know by writing to us at Cyberguy.com/Contact
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
It’s the final day of Prime Day 2025, and the deals are still live

Editor’s note: That’s a wrap, folks! As Prime Day 2025 draws to a close, we’ll no longer be updating this article with additional deals and insights. Plenty of great deals remain, however, so be sure to check out all of our Prime Day coverage for anything you may have missed.
There are mere hours left of Amazon’s extended Prime Day extravaganza. And, yeah, we’re a little exhausted, but after days of lightning deals and all-time low prices, these discounts won’t be around for much longer. So, if you’ve been hesitant to jump on these laptop deals before heading back to school, now’s your time to act. Typically, Prime Day is your last opportunity to take advantage of bottom-dollar prices until Black Friday / Cyber Monday, so it may be a while before you see prices plummet on a gadget you’re interested in buying.
Really, there’s an overwhelming amount of Prime Day deals, so to make things easier to navigate, we’ve organized all of our favorites by category below. That will allow you to quickly find exactly what you’re looking for — or even uncover a deal on something you didn’t know you wanted.
Tablet and e-reader deals
Soundbar and Bluetooth speaker deals
Verge favorites and other miscellaneous deals
Update, July 11th: Added several more deals, including those for Final Fantasy VII Rebirth, Razer’s Kishi Ultra mobile controller, and Amazon’s Fire TV Soundbar Plus.
Technology
Massive scam spreading designed to trick you and steal your money

NEWYou can now listen to Fox News articles!
Look at the image. That’s not the real Omaha Steaks. It’s from a fake site designed to steal your money.
It’s happening all over the internet right now. You see a great deal on name-brand stuff, a new smartwatch, fancy cookware, maybe some designer jeans, and you click.
Everything looks real. The logos, the layout, even Apple and Google Pay are options. But it’s a scam, and now your credit card info is out there.
5-MINUTE CLEANUP FOR YOUR PHONE AND COMPUTER
A massive scam targeting you
Silent Push analysts uncovered thousands of fake websites posing as trusted stores like Apple, Michael Kors, Harbor Freight, REI, Omaha Steaks and more. There’s a massive global scam operation that uses real payment methods on fake checkout pages. Like thousands-of-sites massive.
An image of a fake “Omaha Steaks” website designed to steal your money. (Silent Push)
The twist? The criminals, likely based in China, take your payment and ghost you. No product. No refund. No customer service. Total fake-out.
I’M A TECH PRO AND THESE ARE MY SECRETS TO BETTER FLIGHTS AND LUXURY TRAVEL
They cloned sites
They’re copying everything. Logos, layouts, even the checkout process, so much so that you’d swear you were on the real REI website while buying $10 trail shoes.
But there were some sites with mismatched logos and products. A Harbor Freight clone showed Wrangler jeans.

FILE PHOTO: A photo illustration of a person shopping online. (iStock)
Even worse: These scam sites are popping up faster than hosting companies can take them down. Many are still up right now.
IS YOUR PHONE LISTENING TO EVERYTHING YOU SAY? IT’S COMPLICATED
Don’t fall for it
- Slow down and read. Misspelled words, weird domain names like “nordstromltems.com” (that’s an L, not an I) or random products are huge red flags.
- Use virtual cards or a credit card. Not a debit card. You need that fraud protection.
- Stick to the real URL. Skip the sketchy ads. Always type the URL in yourself.
- If the deal looks too good, it probably is a scam. Period.

FILE PHOTO: A photo illustration of a cybercriminal. (iStock)
Bottom line: If the deal looks like it crawled straight out of your dreams, it’s probably from your nightmares. Slow down before you click “buy.”
Now you know this is happening. This scam campaign is a big one, and you need to stay sharp. Help save the world and use the icons below to share this know-how with your family and friends.
Get tech-smarter on your schedule
Award-winning host Kim Komando is your secret weapon for navigating tech.
- National radio: Airing on 500+ stations across the US – Find yours or get the free podcast.
- Daily newsletter: Join 650,000 people who read the Current (free!)
- Watch: On Kim’s YouTube channel
Copyright 2025, WestStar Multimedia Entertainment. All rights reserved.
-
Business1 week ago
See How Trump’s Big Bill Could Affect Your Taxes, Health Care and Other Finances
-
Politics1 week ago
Video: Trump Signs the ‘One Big Beautiful Bill’ Into Law
-
Culture1 week ago
16 Mayors on What It’s Like to Run a U.S. City Now Under Trump
-
News1 week ago
Video: Who Loses in the Republican Policy Bill?
-
Science1 week ago
Federal contractors improperly dumped wildfire-related asbestos waste at L.A. area landfills
-
Technology1 week ago
Meet Soham Parekh, the engineer burning through tech by working at three to four startups simultaneously
-
World1 week ago
Russia-Ukraine war: List of key events, day 1,227
-
Politics1 week ago
Congressman's last day in office revealed after vote on Trump's 'Big, Beautiful Bill'