Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Crocodilus

161
Global rank
137 infographic chevron month
Month rank
129 infographic chevron week
Week rank

Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.

Trojan
Type
Unknown
Origin
1 March, 2025
First seen
14 September, 2026
Last seen

How to analyze Crocodilus with ANY.RUN

Type
Unknown
Origin
1 March, 2025
First seen
14 September, 2026
Last seen

IOCs

IP addresses
185.15.59.240
142.251.127.81
142.251.156.119
34.104.35.123
142.251.14.94
142.250.154.100
142.251.110.139
216.239.35.8
104.21.56.40
192.178.183.94
172.67.180.66
216.239.35.4
142.251.151.119
142.251.152.119
142.251.155.119
142.251.13.113
192.178.183.113
216.239.35.0
216.239.35.12
142.251.154.119
Hashes
1005a525006f148c86efcbfb36c6eac091b311532448010f70f7de9a68007167
e292f241daafc3df90f3e2d339c61c6e2787a0d0739aac764e1ea9bb8544ee97
378694706fb7256dd2248e2af854efd71ec7e8885f61da2e16a2bd32fcf3d0a9
5a6ca1d0d2fea53813da5b3c9037408087f9f753f58dd2e128a4a48f7689769f
932b2f1a5d1f714742551df4e25b78af1d68d8c3972a3d97ad8d2c24dc13777b
4bc8f4d13d2acccc1338f73ff90cd97695d9210e04de5da924215243c8950bf3
9fd37c82f87df00464554344ddddea55e480d09c33b505ac13252036d4d6276e
4a5c839ab0ce8c0b23a47091bf6a69392c6e11e7e02f31e0889f12c0b1a27cca
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
0ba8cbce9793a324a6d3048e2b21b1be8c6825f70598d470dc2b05974e45fc18
71cc283f39f64025d20f81608d6ed192a09d003c963777795df5bff62cea216a
3325d2a819fdd8062c2cdc48a09b995c9b012915bcdf88b1cf9742a7f057c793
3b9d18d5cc3af6c0cb3e903327ae3da35634c7c3a0b11413b9a3b1c10c640d5e
24d87c1a31c10c48665ad43032523ae7d3eb36583ff0ab734d436f0927b62760
63ac6363a9243c3940407d4220ce683f71ab64c67ad90537dba60a80b3e82a42
e5b179dcd1cb35831a6d29dbd0bea7dd05d02d4e5d3e43930fb2970939435335
1a630de2271ebbc6584dab7c75a0207bfd54262de47e9f5c8bf0350734937b8c
26eeefaf8a7bc3aedf3d8e5de69782ebe9ab09d73da686f84ae4a87bc3ad32c7
46423e677bf3e5f757012a8e431bd908915eeecf1217ad14891abdc2472ce5c2
Domains
www.google.com
google.com
upload.wikimedia.org
clientservices.googleapis.com
connectivitycheck.gstatic.com
beatonlineauction.com
staging-remoteprovisioning.sandbox.googleapis.com
edgedl.me.gvt1.com
update.googleapis.com
powertv.shop
time.android.com
global-tv.lol
play.googleapis.com
orangeuserscar.site
api.telegram.org
testapkapicroco.biz
fonts.gstatic.com
fonts.googleapis.com
s13.gifyu.com
URLs
http://connectivitycheck.gstatic.com/generate_204
https://www.google.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:fetcheekchain
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaaboj8ms10bilsty59wc4_z7zuueibhnxkedcs=&request_id=8d0c41d9-c0f1-4a59-bc13-c1760f88f177
https://clientservices.googleapis.com/chrome-variations/seed?osname=android_webview&milestone=137
https://update.googleapis.com/service/update2/json?cup2key=15:h69ckuqco8vtiaiorbicg-20ez9rmbwjupcedsgu0xs&cup2hreq=935367ba7c5db6e92dd6a5c05f3ecdc71630b67f4bef4857888a2c44e48bebf2
https://update.googleapis.com/service/update2/json
https://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acmmwq7dser4xm5sepzjv74g65vq_2023.7.28.10/cffplpkejcbdpfnfabnjikeicbedmifn_2023.07.28.10_all_acgbwixmcanakp2bkoppyszsbkrq.crx3
https://beatonlineauction.com/pragmatical
https://upload.wikimedia.org/wikipedia/commons/8/87/google_chrome_icon_%282011%29.png
https://update.googleapis.com/service/update2/json?cup2key=15:aq4ndctb6x-ua_2ghqc3h1umlojepevidh_gfnu7hxc&cup2hreq=810088ab7cfbd7c90dc99a8996ca1505fe81f0582779996d945c8b43a127308b
https://powertv.shop/pragmatical
https://update.googleapis.com/service/update2/json?cup2key=15:mvjzgoplb68i1ba2bpjwlgvczmmgbsguaocygsbrzpo&cup2hreq=65e92058b37c41c480474a6261bf398c1d2639550cc5fa7018f95c5b141c271c
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabogj_ogabilsty1ji0hv7zpzy75myzea26e8=&request_id=967d3bc6-d5d5-418d-9f86-2f712911444b
https://update.googleapis.com/service/update2/json?cup2key=15:fjf6bjb9ezsdwumby8z0g4dzkjcczwdx2_br0-ucf68&cup2hreq=d9021cf9470557d3e7a9f631c8224a1c22976a87fc22a193354b7642e4fbd544
https://update.googleapis.com/service/update2/json?cup2key=15:lugorpermv4bmafua_pwokrce--eyijqqgwvkkkb6im&cup2hreq=556665bd3bae6e75094699e3d7a796aa007ba0961dc3226752a0f9879439754f
https://global-tv.lol/pragmatical
http://play.googleapis.com/generate_204
https://staging-remoteprovisioning.sandbox.googleapis.com/v1:signcertificates?challenge=aaabn5q-yb8bilsty9tnk74ybix29oi1t82yyno=&request_id=947fd836-c7d0-4881-ba82-d44628fcca31
https://update.googleapis.com/service/update2/json?cup2key=15:ogon8pavokpy4azqfhm8isjhe7_0tuhduniakrzjlfe&cup2hreq=dffb76958d8fc74fa748edcc9ff5647bedf176d96c06f8adaaee3066c6a09fcb
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 382
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 642
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 2232
comments 0

Crocodilus Malware: The Android Threat That Hides Your Screen While Draining Your Bank Account

Key Takeaways

  • Crocodilus is a fully-featured threat from inception: it emerged with complete device-takeover capabilities including overlay attacks, accessibility abuse, remote control, and advanced social engineering. This represents a concerning trend toward increasingly mature initial threat releases.
  • Mobile devices are critical attack surfaces: organizations must recognize that mobile devices accessing financial and corporate systems represent significant risk vectors.
  • Accessibility Services are the primary attack vector: Crocodilus's power comes from abusing Android Accessibility Services, which grant extensive control over device functionality.

View Crocodilus detonations in ANY.RUN’s Interactive Sandbox to see malicious processes and network connections and understand how the malware acts:

Crocodilus processes in the Sandbox Crocodilus processes detected in the sandbox analysis

Social engineering remains the critical vulnerability: despite technical sophistication, Crocodilus succeeds primarily through convincing social engineering: fake ads, urgent warnings, and trusted caller ID spoofing. Security awareness training focused on mobile-specific threats is essential for both individuals and organizations.

  • Cryptocurrency users face amplified risks: Crocodilus specifically targets cryptocurrency wallets with tailored social engineering to steal seed phrases, representing complete and irreversible compromise.
  • Threat intelligence enables proactive defense: organizations that leverage threat intelligence about Crocodilus can implement specific countermeasures based on known IOCs, distribution methods, and targeted regions. Early intelligence about emerging threats like Crocodilus provides critical time to prepare defenses before widespread attacks.

What is Crocodilus Malware?

Crocodilus is a sophisticated Android banking Trojan that emerged in early 2025, representing a new generation of mobile device-takeover malware. Unlike simpler malicious apps, Crocodilus arrives fully equipped with advanced capabilities including overlay attacks, keylogging, remote access, and hidden remote control features.

It specifically targets banking applications and cryptocurrency wallets, using social engineering tactics to deceive victims into surrendering their most sensitive credentials. Since its discovery, Crocodilus has rapidly evolved and expanded globally.

The malware employs a multi-layered approach to compromise devices, beginning with a proprietary dropper that bypasses Android 13+ security restrictions. Once installed, it requests Accessibility Service permissions, which grants it extensive control over the device.

The malware operates by continuously monitoring app launches and displaying fake overlays to intercept credentials when victims attempt to access legitimate banking or cryptocurrency applications. What distinguishes Crocodilus is its "Accessibility Logger" feature, which goes beyond traditional keylogging by capturing all accessibility events and screen elements, effectively recording everything displayed on the victim's device.

Crocodilus includes remote access trojan (RAT) capabilities that allow attackers to take complete control of infected devices. The malware can display black screen overlays during fraudulent activities, effectively hiding actions from victims while muting device sounds to prevent detection. The malware communicates with command-and-control (C2) servers to receive instructions, download target lists, and exfiltrate stolen data.

Recent variants have introduced even more sophisticated features, including the ability to modify contact lists by adding fake entries that appear as legitimate bank support numbers, and automated seed phrase collectors that use regular expressions to extract cryptocurrency wallet credentials directly from the screen content.

Crocodilus infiltrates via social engineering-driven droppers distributed through:

  • Malicious Ads: Facebook campaigns mimicking banks, browsers (e.g., "Google Chrome update"), or e-commerce apps, redirecting to APK download sites. Polish ads ran thousands of impressions hourly, targeting seniors.
  • Disguised Apps: Posing as online casinos, crypto miners (e.g., "ETH Mining app"), or bonus programs on third-party stores.
  • Sideloading Vectors: SMS phishing or email links leading to droppers that request Accessibility permissions post-install.

Spread relies on C2 orchestration for global campaigns, with no peer-to-peer replication observed. Evolution includes 17+ dropper families for broader compatibility.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Crocodilus Malware Victimology

Crocodilus primarily preys on Android users engaged in financial activities, with campaigns tailored to specific demographics and regions. Initial attacks focused on Spain and Turkey, targeting users of major banks like BBVA and Garanti BBVA, as well as cryptocurrency wallets. By June 2025, its reach expanded to Poland (via ads targeting users over 35), South America (Argentina and Brazil), and broader Europe, including digital banks in the US, Indonesia, and India.

Notable campaigns:

  • Crypto Drain Campaign (April 2025): Infected 1,200+ Android devices across Spain and Turkey, using wallet overlays and RAT hijacks to steal $2.8 million in cryptocurrencies over two weeks. Attackers harvested seed phrases via fake backup prompts.
  • Polish Facebook Blitz (May 2025): Ads mimicking PKO Bank Polski and Allegro e-commerce apps led to hundreds of infections, targeting users over 35 and enabling bank credential theft.
  • Turkish Casino Scam Wave (March-June 2025): Disguised as gambling apps, it hit major banks like Ziraat, resulting in fraudulent transfers estimated at $1.5 million, with fake contacts used for follow-up vishing.
  • Contact List Manipulation Campaign (June 2025): Later variants introduced a new attack vector where Crocodilus added fake contacts to victims' devices using names like "Bank Support" or legitimate financial institution names. Attackers then called victims from these numbers, which appeared as trusted contacts, facilitating successful social engineering attacks that convinced victims to approve fraudulent transactions or reveal additional sensitive information.

How Crocodilus Malware Functions

Crocodilus operates through a multi-stage infection and control process: Stage 1: Initial Installation The malware uses a proprietary dropper application designed to bypass Android 13+ security restrictions. This dropper disguises itself as a legitimate application, often mimicking banking apps, browsers, cryptocurrency tools, or utility applications.

Stage 2: Permission Acquisition Upon installation, Crocodilus immediately requests Accessibility Service permissions. These permissions grant the malware extensive control over the device's user interface and ability to interact with other applications. The malware uses deceptive messaging to convince users to grant these dangerous permissions.

Stage 3: Command and Control Establishment Once permissions are granted, the malware connects to its C2 server to receive operational instructions. This includes downloading lists of target applications (banks and cryptocurrency wallets to monitor) and the corresponding fake overlay screens to deploy.

Stage 4: Continuous Monitoring Crocodilus runs persistently in the background, monitoring which applications the user launches. When a target application is opened, the malware springs into action.

Stage 5: Credential Interception When victims attempt to log into targeted banking or cryptocurrency applications, Crocodilus displays a fake overlay screen that perfectly mimics the legitimate login interface. Users unknowingly enter their credentials into the malicious overlay, which immediately transmits this data to attackers.

Stage 6: Data Exfiltration The malware's accessibility logger captures all screen content, including sensitive information like account balances, transaction details, two-factor authentication codes from Google Authenticator, and cryptocurrency wallet data. For cryptocurrency wallets specifically, the malware employs social engineering to trick users into revealing their seed phrases.

Stage 7: Remote Control Attackers can initiate remote control sessions, taking direct control of the infected device. During these sessions, the malware can display black screen overlays and mute sounds, hiding fraudulent activities from the victim while attackers execute unauthorized transactions, transfer funds, or steal additional information.

Stage 8: Advanced Manipulation Recent variants add fake contacts to the victim's contact list, enabling attackers to call victims while appearing as legitimate bank support or trusted entities. This facilitates additional social engineering attacks and helps bypass fraud prevention systems that flag calls from unknown numbers.

Crocodilus Attack Example and Technical Analysis

ANY.RUN’s Interactive Sandbox supports the detonation and analysis of mobile malware and lets observe its behavior on an actual Android device. Just select an OS in the VM settings on the analysis launch:

OS selection in Sandbox settings Set up virtual environment selecting an Android OS

A Crocodilus sample sandbox analysis demonstrates its signature TTPs like network discovery, evasion, and encryption.

Crocodilus Sandbox analysis Crocodilus in action in the safe Interactive Sandbox environment

Network Activity and Encryption

The malware performs network reconnaissance, extracting the phone number and the name of the current network operator, which allows it to adapt attacks to a specific user and region.

Crocodilus processes: reconnaissance Crocodilus explores network configuration

The analysis shows the use of cryptographic APIs for data encryption, which helps protect transmitted commands and stolen information from interception.

Crocodilus processes: encryption Crocodilus encrypts stolen data

Configuration File and Management

Crocodilus stores its configuration in the SharedPreferences system storage in XML format, where parameters such as the URL of the command server determine the behavior of the malware.

Crocodilus configuration file Crocodilus’ configuration file

Persistence and Privilege Escalation

To remain stealthy, Crocodilus hides the application icon from the screen and blocks deletion attempts by intercepting events in Android settings. Besides, it requests access to accessibility services and intercepts their events, allowing interface manipulation without user input. The malware uses accessibility to control applications, automatically performing actions such as button taps, for privilege escalation and overlay attacks.

Crocodilus develops its persistence and privileges Crocodilus develops its persistence and privileges

Screen Capture, Keylogging, and Overlay Attacks

Keylogging through screen capture is implemented as an Accessibility Logger. The malware monitors all accessibility events, capturing elements displayed on the screen, including user’s text input. This allows recording not only keystrokes but also dynamic content, such as one-time passwords from applications like Google Authenticator.

Overlay attacks are the main tool for stealing credentials. When a user launches a target application, such as a banking or crypto wallet, the malware overlays a fake screen on top of the real one, imitating the login interface to capture logins and passwords.

How Crocodilus Malware Threatens Businesses and Organizations

While Crocodilus primarily targets individual users, its impact extends significantly to businesses and organizations through multiple attack vectors:

Bring Your Own Device (BYOD) Risks: If an employee's infected device accesses company banking applications, financial systems, or corporate accounts, the malware can compromise business financial assets.

Financial Fraud and Direct Losses: Organizations that conduct mobile banking or maintain cryptocurrency treasuries face direct financial theft.

Data Breach and Compliance Violations: Crocodilus captures sensitive business communications, credentials, and financial data. For organizations subject to regulations like GDPR, PCI DSS, or financial services regulations, such breaches can result in substantial fines, legal liabilities, and mandatory breach notifications.

Business Email Compromise (BEC) Enablement: By accessing business communications and contact lists on infected devices, attackers gain intelligence for BEC attacks. They can impersonate executives, understand business relationships, and craft convincing fraud attempts targeting other employees or business partners.

Reputational Damage: Organizations that fall victim to Crocodilus-enabled fraud may suffer significant reputational harm, especially if customer data or funds are compromised.

Supply Chain Threats: Infected devices used by vendors, contractors, or partners can serve as entry points into broader business ecosystems, potentially compromising multiple organizations through a single infection.

Gathering Threat Intelligence on Crocodilus Malware

Threat intelligence provides specific technical indicators including file hashes, C2 server domains, malicious package names, and behavioral signatures. Security teams can integrate these IOCs into security tools, endpoint protection platforms, and network security devices to identify and block Crocodilus-related activity.

Start from querying Threat Intelligence Lookup with the threat name to find Crocodilus samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather IOCs:

threatName:"crocodilus"

Crocodilus sandbox analyses found via TI Lookup Crocodilus sandbox analyses found via TI Lookup

Add a country code to the request to see how actively Crocodilus samples has been recently analyzed by the Sandbox users from this country and suggest whether the region is heavily targeted right now. In this example, German does not seem to be under fire yet, which means local companies and users still have some time to prepare:

threatName:"crocodilus" AND submissionCountry:"de"

Crocodilus samples analyzed from Germany Crocodilus samples submitted to the Sandbox from Germany

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Crocodilus exemplifies the accelerating arms race in mobile malware, blending RAT sophistication with global scalability to erode trust in digital finance. From its Turkish roots to worldwide bites, it demands a unified response: vigilant users, fortified apps, and shared intelligence. As Android's dominance grows, ignoring such threats risks financial chaos—but armed with awareness, we can clamp down before it snaps again.

Start gathering actionable threat intelligence on Crocodilus by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Ramnit screenshot
Ramnit
ramnit
Ramnit is a highly modular banking trojan and worm that evolved from a file-infecting virus into a powerful cybercrime tool. It specializes in financial fraud, credential theft, remote access, and malware delivery, being a serious threat to businesses and individuals. First spotted in 2010, Ramnit became popular after the 2014 takedown of the GameOver Zeus botnet, as cybercriminals sought alternatives for banking fraud.
Read More
DonutLoader screenshot
DonutLoader
donutloader donut
DonutLoader is a versatile, open-source-based in-memory loader that turns .NET assemblies, executables, DLLs, and scripts into position-independent shellcode for execution entirely in RAM. Originally derived from the popular Donut tool, it enables threat actors to bypass traditional antivirus and EDR solutions by avoiding disk writes and injecting payloads directly into legitimate Windows processes.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More