Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Crocodilus

171
Global rank
186 infographic chevron month
Month rank
181 infographic chevron week
Week rank
0
IOCs

Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.

Trojan
Type
Unknown
Origin
1 March, 2025
First seen
25 July, 2026
Last seen

How to analyze Crocodilus with ANY.RUN

Type
Unknown
Origin
1 March, 2025
First seen
25 July, 2026
Last seen

IOCs

IP addresses
142.251.110.100
172.217.117.4
142.250.154.94
142.251.127.81
185.15.59.240
142.251.154.119
142.251.110.138
216.239.35.0
142.251.151.119
34.104.35.123
142.251.157.119
216.239.35.8
142.250.154.138
142.251.20.94
104.21.61.116
142.251.143.14
142.251.155.119
149.154.166.110
142.251.110.94
142.251.153.119
Hashes
b44eeda34d7a529c2fe55719eb098fa29707caa91d18de06a7a775d6e6bcf973
734c1f61bd507bb4f4c1fb28620d163ef158e2c19dfa94f344e18d4e2fd0ec5e
8430ec003e003f3f2ba2f78d48fd150e25407667e530e82e87a7d4841c0fd676
0d773e62c756422313262846c787e58f67e0ee87e45e1ae9942002e816c4cb9e
e44d95e57172603aa992ffdb6bb9a302f945f00b632a5f7c6c29b873161e9aa9
67691e44662856541bc59f56439342fd7ee9e985109d5a8819a4b746bc8718da
9f856dd00a4f281d1198e6679ac8611fc67d301f28c07aea97504244ba16cb44
59854984853104df5c353e2f681a15fc7924742f9a2e468c29af248dce45ce03
cc52f678848b814373757b460383bf61960e4943c203735adde0a350b3e50989
bb9f8df61474d25e71fa00722318cd387396ca1736605e1248821cc0de3d3af8
38d377afa76b6364e5bf551cf4ffec1a881a46102a0047f523fbf148e0df6928
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
e5becd9ca5472dedb2578fddbefc65281c4543ab63a001827f7ad7ebb873d005
e65b8a58330ea4a8f79136af30ca8dc21df600e16b79da9b7380c91ddab80bd3
8e89bbb65cdd9fffc294660ba897eb044424a9f80306f1f1f165aeea01d9b8ec
c0e62b9671b6186283074a91e262f26ca70714208f2390e00dc438e733931c8e
c36f83024507353e1e3c7304faac4aaf36ce628d735707a52f18c7c03f380350
e9ffa2aa0cd2c9a1b7ec5f7d0a6a71cd8048d0b92c7a97a2f7b36f467a063300
3f535b9605350fb5298d1914c425ef11b76277145110f1d43c41924b3296046d
0403824ed6f7e330f6efd0311ab1af5f938fa189108932a7735b52b05c0a300b
Domains
google.com
staging-remoteprovisioning.sandbox.googleapis.com
edgedl.me.gvt1.com
upload.wikimedia.org
play.googleapis.com
update.googleapis.com
clientservices.googleapis.com
time.android.com
www.google.com
connectivitycheck.gstatic.com
orangeuserscar.site
api.telegram.org
testapkapicroco.biz
fonts.gstatic.com
fonts.googleapis.com
s13.gifyu.com
URLs
http://connectivitycheck.gstatic.com/generate_204
http://play.googleapis.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn5q-yb8bilsty9tnk74ybix29oi1t82yyno=&request_id=947fd836-c7d0-4881-ba82-d44628fcca31
https://update.googleapis.com/service/update2/json?cup2key=15:ogon8pavokpy4azqfhm8isjhe7_0tuhduniakrzjlfe&cup2hreq=dffb76958d8fc74fa748edcc9ff5647bedf176d96c06f8adaaee3066c6a09fcb
https://update.googleapis.com/service/update2/json
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://upload.wikimedia.org/wikipedia/commons/8/87/google_chrome_icon_%282011%29.png
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnb_dfrabilstywv1vonxv-6ydz7gkx1gc1m=&request_id=b5966287-7271-4906-8b2b-4d0b9cbc0312
https://update.googleapis.com/service/update2/json?cup2key=15:xajckqcw2d93vskp1jkyuhj644dhpwtxmseualkbzwq&cup2hreq=a5b9963a84b0d673db8f815c88f4e74db611ded6b2f8e11d6dff16ad4d2fba85
https://orangeuserscar.site/villaburada
https://api.telegram.org/bot8055029511:aah3af978hukj7x2j7c-z4tuohmd9eifa-o/sendmessage?chat_id=7547984349&text=hata+14001%3a+nuneuhmsv+sendtoserver%28%29+crash%3a+unable+to+resolve+host+%22twtliquidity.pro%22%3a+no+address+associated+with+hostname
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabnb7qofibilstyzgkifoosm3hqbhmujvise0=&request_id=6f0725a7-05c0-4662-b04f-2816ea757f48
https://update.googleapis.com/service/update2/json?cup2key=15:bn8ewmjglqbo1_wyronbe6tfs0rxg91j_23v68oejys&cup2hreq=bc61a8950ac6a26a400511c2684fe6f45d4f4f31acae10fb11afd943d4950d44
https://api.telegram.org/bot8055029511:aah3af978hukj7x2j7c-z4tuohmd9eifa-o/sendmessage?chat_id=7547984349&text=hata+14001%3a+nuneuhmsv+sendtoserver%28%29+crash%3a+unable+to+resolve+host+%220f62765de805f6b.net%22%3a+no+address+associated+with+hostname
https://api.telegram.org/bot8055029511:aah3af978hukj7x2j7c-z4tuohmd9eifa-o/sendmessage?chat_id=7547984349&text=hata+14001%3a+nuneuhmsv+sendtoserver%28%29+crash%3a+unable+to+resolve+host+%220f62765de805f6b.homes%22%3a+no+address+associated+with+hostname
https://api.telegram.org/bot8055029511:aah3af978hukj7x2j7c-z4tuohmd9eifa-o/sendmessage?chat_id=7547984349&text=hata+14001%3a+nuneuhmsv+sendtoserver%28%29+crash%3a+unable+to+resolve+host+%220f62765de805f6b.com%22%3a+no+address+associated+with+hostname
https://api.telegram.org/bot8055029511:aah3af978hukj7x2j7c-z4tuohmd9eifa-o/sendmessage?chat_id=7547984349&text=hata+14001%3a+nuneuhmsv+sendtoserver%28%29+crash%3a+unable+to+resolve+host+%220f62765de805f6b.click%22%3a+no+address+associated+with+hostname
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

Crocodilus Malware: The Android Threat That Hides Your Screen While Draining Your Bank Account

Key Takeaways

  • Crocodilus is a fully-featured threat from inception: it emerged with complete device-takeover capabilities including overlay attacks, accessibility abuse, remote control, and advanced social engineering. This represents a concerning trend toward increasingly mature initial threat releases.
  • Mobile devices are critical attack surfaces: organizations must recognize that mobile devices accessing financial and corporate systems represent significant risk vectors.
  • Accessibility Services are the primary attack vector: Crocodilus's power comes from abusing Android Accessibility Services, which grant extensive control over device functionality.

View Crocodilus detonations in ANY.RUN’s Interactive Sandbox to see malicious processes and network connections and understand how the malware acts:

Crocodilus processes in the Sandbox Crocodilus processes detected in the sandbox analysis

Social engineering remains the critical vulnerability: despite technical sophistication, Crocodilus succeeds primarily through convincing social engineering: fake ads, urgent warnings, and trusted caller ID spoofing. Security awareness training focused on mobile-specific threats is essential for both individuals and organizations.

  • Cryptocurrency users face amplified risks: Crocodilus specifically targets cryptocurrency wallets with tailored social engineering to steal seed phrases, representing complete and irreversible compromise.
  • Threat intelligence enables proactive defense: organizations that leverage threat intelligence about Crocodilus can implement specific countermeasures based on known IOCs, distribution methods, and targeted regions. Early intelligence about emerging threats like Crocodilus provides critical time to prepare defenses before widespread attacks.

What is Crocodilus Malware?

Crocodilus is a sophisticated Android banking Trojan that emerged in early 2025, representing a new generation of mobile device-takeover malware. Unlike simpler malicious apps, Crocodilus arrives fully equipped with advanced capabilities including overlay attacks, keylogging, remote access, and hidden remote control features.

It specifically targets banking applications and cryptocurrency wallets, using social engineering tactics to deceive victims into surrendering their most sensitive credentials. Since its discovery, Crocodilus has rapidly evolved and expanded globally.

The malware employs a multi-layered approach to compromise devices, beginning with a proprietary dropper that bypasses Android 13+ security restrictions. Once installed, it requests Accessibility Service permissions, which grants it extensive control over the device.

The malware operates by continuously monitoring app launches and displaying fake overlays to intercept credentials when victims attempt to access legitimate banking or cryptocurrency applications. What distinguishes Crocodilus is its "Accessibility Logger" feature, which goes beyond traditional keylogging by capturing all accessibility events and screen elements, effectively recording everything displayed on the victim's device.

Crocodilus includes remote access trojan (RAT) capabilities that allow attackers to take complete control of infected devices. The malware can display black screen overlays during fraudulent activities, effectively hiding actions from victims while muting device sounds to prevent detection. The malware communicates with command-and-control (C2) servers to receive instructions, download target lists, and exfiltrate stolen data.

Recent variants have introduced even more sophisticated features, including the ability to modify contact lists by adding fake entries that appear as legitimate bank support numbers, and automated seed phrase collectors that use regular expressions to extract cryptocurrency wallet credentials directly from the screen content.

Crocodilus infiltrates via social engineering-driven droppers distributed through:

  • Malicious Ads: Facebook campaigns mimicking banks, browsers (e.g., "Google Chrome update"), or e-commerce apps, redirecting to APK download sites. Polish ads ran thousands of impressions hourly, targeting seniors.
  • Disguised Apps: Posing as online casinos, crypto miners (e.g., "ETH Mining app"), or bonus programs on third-party stores.
  • Sideloading Vectors: SMS phishing or email links leading to droppers that request Accessibility permissions post-install.

Spread relies on C2 orchestration for global campaigns, with no peer-to-peer replication observed. Evolution includes 17+ dropper families for broader compatibility.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Crocodilus Malware Victimology

Crocodilus primarily preys on Android users engaged in financial activities, with campaigns tailored to specific demographics and regions. Initial attacks focused on Spain and Turkey, targeting users of major banks like BBVA and Garanti BBVA, as well as cryptocurrency wallets. By June 2025, its reach expanded to Poland (via ads targeting users over 35), South America (Argentina and Brazil), and broader Europe, including digital banks in the US, Indonesia, and India.

Notable campaigns:

  • Crypto Drain Campaign (April 2025): Infected 1,200+ Android devices across Spain and Turkey, using wallet overlays and RAT hijacks to steal $2.8 million in cryptocurrencies over two weeks. Attackers harvested seed phrases via fake backup prompts.
  • Polish Facebook Blitz (May 2025): Ads mimicking PKO Bank Polski and Allegro e-commerce apps led to hundreds of infections, targeting users over 35 and enabling bank credential theft.
  • Turkish Casino Scam Wave (March-June 2025): Disguised as gambling apps, it hit major banks like Ziraat, resulting in fraudulent transfers estimated at $1.5 million, with fake contacts used for follow-up vishing.
  • Contact List Manipulation Campaign (June 2025): Later variants introduced a new attack vector where Crocodilus added fake contacts to victims' devices using names like "Bank Support" or legitimate financial institution names. Attackers then called victims from these numbers, which appeared as trusted contacts, facilitating successful social engineering attacks that convinced victims to approve fraudulent transactions or reveal additional sensitive information.

How Crocodilus Malware Functions

Crocodilus operates through a multi-stage infection and control process: Stage 1: Initial Installation The malware uses a proprietary dropper application designed to bypass Android 13+ security restrictions. This dropper disguises itself as a legitimate application, often mimicking banking apps, browsers, cryptocurrency tools, or utility applications.

Stage 2: Permission Acquisition Upon installation, Crocodilus immediately requests Accessibility Service permissions. These permissions grant the malware extensive control over the device's user interface and ability to interact with other applications. The malware uses deceptive messaging to convince users to grant these dangerous permissions.

Stage 3: Command and Control Establishment Once permissions are granted, the malware connects to its C2 server to receive operational instructions. This includes downloading lists of target applications (banks and cryptocurrency wallets to monitor) and the corresponding fake overlay screens to deploy.

Stage 4: Continuous Monitoring Crocodilus runs persistently in the background, monitoring which applications the user launches. When a target application is opened, the malware springs into action.

Stage 5: Credential Interception When victims attempt to log into targeted banking or cryptocurrency applications, Crocodilus displays a fake overlay screen that perfectly mimics the legitimate login interface. Users unknowingly enter their credentials into the malicious overlay, which immediately transmits this data to attackers.

Stage 6: Data Exfiltration The malware's accessibility logger captures all screen content, including sensitive information like account balances, transaction details, two-factor authentication codes from Google Authenticator, and cryptocurrency wallet data. For cryptocurrency wallets specifically, the malware employs social engineering to trick users into revealing their seed phrases.

Stage 7: Remote Control Attackers can initiate remote control sessions, taking direct control of the infected device. During these sessions, the malware can display black screen overlays and mute sounds, hiding fraudulent activities from the victim while attackers execute unauthorized transactions, transfer funds, or steal additional information.

Stage 8: Advanced Manipulation Recent variants add fake contacts to the victim's contact list, enabling attackers to call victims while appearing as legitimate bank support or trusted entities. This facilitates additional social engineering attacks and helps bypass fraud prevention systems that flag calls from unknown numbers.

Crocodilus Attack Example and Technical Analysis

ANY.RUN’s Interactive Sandbox supports the detonation and analysis of mobile malware and lets observe its behavior on an actual Android device. Just select an OS in the VM settings on the analysis launch:

OS selection in Sandbox settings Set up virtual environment selecting an Android OS

A Crocodilus sample sandbox analysis demonstrates its signature TTPs like network discovery, evasion, and encryption.

Crocodilus Sandbox analysis Crocodilus in action in the safe Interactive Sandbox environment

Network Activity and Encryption

The malware performs network reconnaissance, extracting the phone number and the name of the current network operator, which allows it to adapt attacks to a specific user and region.

Crocodilus processes: reconnaissance Crocodilus explores network configuration

The analysis shows the use of cryptographic APIs for data encryption, which helps protect transmitted commands and stolen information from interception.

Crocodilus processes: encryption Crocodilus encrypts stolen data

Configuration File and Management

Crocodilus stores its configuration in the SharedPreferences system storage in XML format, where parameters such as the URL of the command server determine the behavior of the malware.

Crocodilus configuration file Crocodilus’ configuration file

Persistence and Privilege Escalation

To remain stealthy, Crocodilus hides the application icon from the screen and blocks deletion attempts by intercepting events in Android settings. Besides, it requests access to accessibility services and intercepts their events, allowing interface manipulation without user input. The malware uses accessibility to control applications, automatically performing actions such as button taps, for privilege escalation and overlay attacks.

Crocodilus develops its persistence and privileges Crocodilus develops its persistence and privileges

Screen Capture, Keylogging, and Overlay Attacks

Keylogging through screen capture is implemented as an Accessibility Logger. The malware monitors all accessibility events, capturing elements displayed on the screen, including user’s text input. This allows recording not only keystrokes but also dynamic content, such as one-time passwords from applications like Google Authenticator.

Overlay attacks are the main tool for stealing credentials. When a user launches a target application, such as a banking or crypto wallet, the malware overlays a fake screen on top of the real one, imitating the login interface to capture logins and passwords.

How Crocodilus Malware Threatens Businesses and Organizations

While Crocodilus primarily targets individual users, its impact extends significantly to businesses and organizations through multiple attack vectors:

Bring Your Own Device (BYOD) Risks: If an employee's infected device accesses company banking applications, financial systems, or corporate accounts, the malware can compromise business financial assets.

Financial Fraud and Direct Losses: Organizations that conduct mobile banking or maintain cryptocurrency treasuries face direct financial theft.

Data Breach and Compliance Violations: Crocodilus captures sensitive business communications, credentials, and financial data. For organizations subject to regulations like GDPR, PCI DSS, or financial services regulations, such breaches can result in substantial fines, legal liabilities, and mandatory breach notifications.

Business Email Compromise (BEC) Enablement: By accessing business communications and contact lists on infected devices, attackers gain intelligence for BEC attacks. They can impersonate executives, understand business relationships, and craft convincing fraud attempts targeting other employees or business partners.

Reputational Damage: Organizations that fall victim to Crocodilus-enabled fraud may suffer significant reputational harm, especially if customer data or funds are compromised.

Supply Chain Threats: Infected devices used by vendors, contractors, or partners can serve as entry points into broader business ecosystems, potentially compromising multiple organizations through a single infection.

Gathering Threat Intelligence on Crocodilus Malware

Threat intelligence provides specific technical indicators including file hashes, C2 server domains, malicious package names, and behavioral signatures. Security teams can integrate these IOCs into security tools, endpoint protection platforms, and network security devices to identify and block Crocodilus-related activity.

Start from querying Threat Intelligence Lookup with the threat name to find Crocodilus samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather IOCs:

threatName:"crocodilus"

Crocodilus sandbox analyses found via TI Lookup Crocodilus sandbox analyses found via TI Lookup

Add a country code to the request to see how actively Crocodilus samples has been recently analyzed by the Sandbox users from this country and suggest whether the region is heavily targeted right now. In this example, German does not seem to be under fire yet, which means local companies and users still have some time to prepare:

threatName:"crocodilus" AND submissionCountry:"de"

Crocodilus samples analyzed from Germany Crocodilus samples submitted to the Sandbox from Germany

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Crocodilus exemplifies the accelerating arms race in mobile malware, blending RAT sophistication with global scalability to erode trust in digital finance. From its Turkish roots to worldwide bites, it demands a unified response: vigilant users, fortified apps, and shared intelligence. As Android's dominance grows, ignoring such threats risks financial chaos—but armed with awareness, we can clamp down before it snaps again.

Start gathering actionable threat intelligence on Crocodilus by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
Backdoor screenshot
Backdoor
backdoor
A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
DarkGate screenshot
DarkGate
darkgate
DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors.
Read More
DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More