DiscoverCYFIRMA ResearchCYFIRMA Research- SeedSnatcher: Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases
CYFIRMA Research- SeedSnatcher: Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases

CYFIRMA Research- SeedSnatcher: Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases

Update: 2025-12-18
Share

Description

Mobile Threat Alert: Crypto Mnemonic Phrase Stealer

SeedSnatcher is a newly uncovered Android malware family targeting the crypto ecosystem, built to steal users’ mnemonic recovery phrases using a sophisticated DisplayOverlay attack

Capabilities:

  • Intercepts and exfiltrates seed phrases and private keys from major cryptocurrency wallets
  • Presents deceptive wallet-import screens to lure users into entering their recovery phrases
  • Communicates with its command-and-control servers via encrypted WebSocket channels

Additional Capabilities:

  • Access device files and media
  • Read SMS content and monitor messages
  • Retrieve call logs and contact lists
  • Collect device identifiers, network data, and app details
  • Exfiltrate collected information to the C2 over encrypted channels


Link to the Research Report: SEEDSNATCHER : Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases - CYFIRMA

#CyberSecurity #MobileSecurity #AndroidMalware #CryptoSecurity  #ThreatIntelligence #SeedSnatcher #ThreatAlert #CYFIRMA #CYFIRMAresearch#ExternalThreatLandscapeManagement #ETLM

https://www.cyfirma.com/

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

CYFIRMA Research- SeedSnatcher: Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases

CYFIRMA Research- SeedSnatcher: Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic Phrases

CYFIRMA