Crocodilus is an Android banking Trojan discovered in March 2025 that combines credential theft, cryptocurrency-wallet secret extraction, and remote device takeover to facilitate financial fraud. Initial campaigns targeted banking users in Spain and Turkey; subsequent activity expanded across Europe, South America, and other regions. Distribution includes malicious advertising and applications impersonating banking, e-commerce, casino, cryptocurrency-mining, and browser-update software. A dedicated dropper supports installation while bypassing Android 13 and later restrictions.
After installation, Crocodilus persuades victims to enable an Accessibility service, which it abuses to monitor application launches, inspect screen content, log text changes, and execute attacker-controlled gestures. It obtains target application lists and overlay configurations from command-and-control infrastructure and displays fraudulent login screens over financial applications. Its Accessibility-based collection captures credentials, cryptocurrency private keys and recovery phrases, and Google Authenticator one-time codes. Wallet-targeting overlays pressure victims to reveal their recovery phrases under the pretext of backing up wallet access. Crocodilus also collects SMS messages, contacts, and device information, sends SMS messages to specified recipients or all contacts, and executes USSD requests.
Remote-control functionality allows operators to interact with the infected device and conduct fraudulent transactions. Hidden operation uses a black screen overlay and device muting to conceal attacker activity. Updated variants insert attacker-specified names and telephone numbers into the address book, enabling subsequent calls to appear associated with trusted organizations such as banks.
Crocodilus employs code packing, encrypted payloads, string obfuscation, and convoluted code to hinder analysis. An analyzed variant uses malformed APK archive headers to disrupt parsing, dynamically loads a decrypted payload, and deletes the decrypted file afterward. Command-and-control communication uses HTTP and WebSocket connections, with encryption and additional encoding protecting HTTP message contents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This environment has paved the way for the emergence of Crocodilus, a new and highly capable mobile banking Trojan discovered by ThreatFabric.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
These include: Code packing for both the dropper and payload Additional XOR encryption of the payload (Crocodilus) to conceal it during analysis Entangled, convoluted code to complicate reverse engineering
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
This variant was equipped with an additional parser, helping to extract seed phrases and private keys of specific wallets.
Once installed, Crocodilus actively monitors the launch of Turkish financial apps, overlaying them with fake login pages.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that abuses user-granted Accessibility permissions to steal credentials, cryptocurrency private keys and seed phrases, and Google Authenticator codes. Its RAT capabilities include remotely executing gestures, extracting UI information, concealing activity, and inserting attacker-specified contacts for social engineering. The analyzed variant impersonates Chrome and uses a two-stage packer that decrypts an embedded DEX payload, dynamically loads it, and deletes the decrypted file from disk. Modified APK ZIP headers obstruct analysis and, in the reported test, caused Google Play Protect scanning to fail while returning a SAFE verdict. C2 communication uses HTTP and WebSockets, with AES-CBC encryption and additional Base64 and string-reversal obfuscation. The content identifies Pragma Project as a codename observed in a variant.
Mentioned only as a comparison for abuse of Android Accessibility permissions.
Mentioned only as a comparison for Android Accessibility-permission abuse.
Referenced as a comparison point for similar use of accessibility abuse and overlay attacks against financial apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.