Crocodilus is an Android banking Trojan first publicly identified in 2025 that follows a modern device-takeover model aimed at financial fraud. It targets mobile banking applications and cryptocurrency wallets, initially focusing on users in Turkey and Spain before expanding into broader campaigns across Europe, South America, and other regions. The malware has been associated with lures including fake banking applications, counterfeit browser updates, malicious advertising, and other fraudulent Android apps designed to persuade victims to install a dropper and grant Accessibility permissions.
Once active, Crocodilus abuses Android Accessibility Services to monitor application launches, capture on-screen content, log user input, and automate interaction with targeted apps. It performs overlay attacks against financial applications to steal credentials, can collect SMS messages, harvest contact lists, send SMS messages, and issue USSD requests. The malware also supports remote device takeover functions, including concealed attacker activity through a black-screen overlay and muting of the device to reduce user awareness during fraudulent operations.
Crocodilus is notable for targeting cryptocurrency users in addition to traditional banking victims. It uses social-engineering prompts and accessibility-based collection to extract wallet recovery material, including seed phrases, and later variants added parsing logic to better extract wallet data from targeted applications. It has also been observed capturing one-time codes from authenticator applications, enabling attackers to bypass additional authentication controls.
Recent variants introduced stronger obfuscation and payload concealment, including packing and encrypted components, and added the ability to insert attacker-controlled contacts into a victim’s address book. This contact manipulation supports follow-on social engineering by making attacker communications appear to come from trusted entities such as bank support. Early reporting suggested a possible connection to the mobile threat actor sybra, but that linkage remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment has paved the way for the emergence of Crocodilus, a new and highly capable mobile banking Trojan discovered by ThreatFabric.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
These include: Code packing for both the dropper and payload Additional XOR encryption of the payload (Crocodilus) to conceal it during analysis Entangled, convoluted code to complicate reverse engineering
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
This variant was equipped with an additional parser, helping to extract seed phrases and private keys of specific wallets.
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another Android banking threat that uses user-granted access to broaden impact.
Android malware that manipulates victims' contact lists to help attackers impersonate trusted entities such as banks.
Referenced as an Android banking malware family that similarly abuses Android Accessibility services for banking fraud/credential theft techniques.
Android banking malware abusing Accessibility services for credential theft and data harvesting; includes remote control and overlay/black-screen techniques; targets Spain and Turkey.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.