Crocodilus is an Android banking Trojan and device-takeover malware first identified in March 2025. It targets mobile banking applications and cryptocurrency wallets, initially concentrating on Spain and Turkey before expanding campaigns across Europe, South America, and other regions. Operators distribute it through malicious advertising and deceptive applications masquerading as banking, e-commerce, cryptocurrency-mining, online-casino, or browser-update software. A proprietary dropper has been used to circumvent Android 13-and-later installation restrictions.
Crocodilus abuses Android Accessibility Services to monitor application launches, inspect displayed interface content, log text-entry events, and perform actions on behalf of an operator. It deploys fraudulent overlays over targeted financial applications to capture login credentials and can collect one-time passwords from Google Authenticator and SMS messages. It also uses wallet-themed social-engineering overlays to induce victims to reveal recovery seed phrases; newer variants parse accessibility-derived screen data to extract seed phrases and private keys from cryptocurrency wallet applications.
The malware supports remote device control and can conceal fraudulent activity by presenting a black-screen overlay and muting the device. It can collect contacts, alter the victim address book by inserting attacker-selected entries, send SMS messages to selected recipients or all contacts, execute USSD requests, and collect SMS data. Contact manipulation can facilitate impersonation of trusted entities, including purported bank-support contacts. Recent versions use code packing, encrypted payloads, and deliberately convoluted code to impede analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment has paved the way for the emergence of Crocodilus, a new and highly capable mobile banking Trojan discovered by ThreatFabric.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
These include: Code packing for both the dropper and payload Additional XOR encryption of the payload (Crocodilus) to conceal it during analysis Entangled, convoluted code to complicate reverse engineering
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
This variant was equipped with an additional parser, helping to extract seed phrases and private keys of specific wallets.
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison for abuse of Android Accessibility permissions.
Mentioned only as a comparison for Android Accessibility-permission abuse.
Referenced as a comparison point for similar use of accessibility abuse and overlay attacks against financial apps.
Referenced as another Android banking threat that uses user-granted access to broaden impact.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.