Crocodilus is an Android banking trojan focused on device takeover, credential theft, and financial fraud against mobile banking and cryptocurrency-wallet users. It was identified as a distinct malware family with mature capabilities at first discovery, including overlay-based credential harvesting, accessibility-driven keylogging and screen-content collection, remote-control functions, and stealth features designed to conceal attacker activity during fraudulent operations.
The malware is installed via a dropper and then pressures victims to grant Android Accessibility Service permissions. Once elevated through accessibility abuse, it communicates with command-and-control infrastructure to obtain target application lists, overlay configurations, and operational commands. It monitors application launches and presents fake screens over legitimate banking and wallet apps to intercept credentials and other sensitive inputs. Its accessibility logging captures interface text and user interactions, enabling broad harvesting beyond simple keystrokes.
Crocodilus has been observed targeting banks initially in Spain and Turkey and later expanding globally, with activity reported across additional regions including parts of Europe, South America, and Asia. It also targets cryptocurrency wallets and uses social engineering to trick victims into exposing wallet recovery material. In wallet-focused attacks, it prompts users to perform urgent backup actions so the malware can capture seed phrases through accessibility monitoring, enabling complete theft of wallet assets.
Beyond credential theft, Crocodilus can collect SMS messages, send SMS messages, perform USSD requests, and manipulate contact lists. Contact-list abuse supports impersonation of trusted entities such as banks and can facilitate follow-on social engineering. The malware has also been reported to capture one-time passcodes from authenticator applications, further supporting account takeover and transaction fraud.
For stealth and post-compromise control, Crocodilus can mute the device and display a black-screen overlay while operators remotely interact with the phone, reducing the likelihood that victims notice fraudulent actions in progress. Reporting has also noted hidden remote-control behavior consistent with modern Android banking trojans that aim to take full control of the victim device rather than relying solely on static overlays.
Observed delivery methods include malicious advertising, fake banking applications, and fake browser-update lures. Early analysis suggested a possible connection to the mobile threat actor sybra based on sample tagging, though the exact relationship between that actor and Crocodilus development or operation remains unconfirmed. Source-code debug artifacts have indicated likely Turkish-speaking developers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment has paved the way for the emergence of Crocodilus, a new and highly capable mobile banking Trojan discovered by ThreatFabric.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Once installed, Crocodilus requests Accessibility Service to be enabled. Once granted, the malware connects to the command-and-control (C2) server to receive instructions... Another data theft feature of Crocodilus is a keylogger. However, it is more accurate to call it an Accessibility Logger – the malware monitors all Accessibility events and captures all the elements displayed on the screen.
Once installed, Crocodilus requests Accessibility Service to be enabled. Once granted, the malware connects to the command-and-control (C2) server to receive instructions... Another data theft feature of Crocodilus is a keylogger. However, it is more accurate to call it an Accessibility Logger – the malware monitors all Accessibility events and captures all the elements displayed on the screen.
It runs continuously, monitoring app launches and displaying overlays to intercept credentials.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another Android banking threat that uses user-granted access to broaden impact.
Android malware that manipulates victims' contact lists to help attackers impersonate trusted entities such as banks.
Referenced as an Android banking malware family that similarly abuses Android Accessibility services for banking fraud/credential theft techniques.
Android banking malware abusing Accessibility services for credential theft and data harvesting; includes remote control and overlay/black-screen techniques; targets Spain and Turkey.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.