Security researchers have identified Crocodilus, a new and rapidly evolving Android banking Trojan, being used in campaigns that target both banking app users and cryptocurrency users across multiple countries in Europe and Asia, including Turkey and Spain. The malware is designed for full device takeover, enabling attackers to steal banking credentials, crypto wallet seed phrases and private keys, intercept one-time passwords (OTPs), and perform fraudulent transactions remotely without the victim’s awareness. Crocodilus was first reported in March 2025 by ThreatFabric as a distinct Android malware family equipped with a full modern banking‑Trojan toolset: overlay attacks that place fake login screens over legitimate apps, keylogging, remote access, and a “hidden” mode that shows a black screen while attackers control the device. Initial campaigns were observed in Turkey and Spain, where the malware sometimes masqueraded as Google Chrome or legitimate financial tools, but later activity shows expansion to other European countries and to South America, while still prioritizing targets in Turkey and broader European regions. Distribution methods include malicious advertising and droppers that pose as QR code scanners, crypto portfolio trackers, phone boosters, or finance apps, which then request powerful Accessibility and Device Administrator permissions to gain control of the phone. A key reason this threat is significant for crypto and banking users is Crocodilus’s focus on financial data extraction: it monitors when users open banking or cryptocurrency apps, displays pixel‑perfect overlays to harvest credentials, logs accessibility events to capture OTPs (even from apps like Google Authenticator), and, in newer variants, automatically searches for and exfiltrates crypto wallet seed phrases and private keys using tailored regular expressions. Once it has credentials and OTPs, the malware can log in to accounts, initiate transfers, mute notifications, hide SMS messages, and even add fake “support” contacts to help trick victims into sharing additional verification codes. Security vendors warn that Crocodilus is becoming more sophisticated, with variants using native code and improved obfuscation to evade detection, highlighting the need for users—particularly in affected regions and anyone handling funds on Android—to avoid sideloaded apps, scrutinize permission requests, and regularly review devices for suspicious apps and elevated permissions.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on malware

Comments