A sophisticated Android banking trojan called Crocodilus is rapidly expanding its reach beyond its initial targets in Europe to affect users across multiple continents. According to recent findings by ThreatFabric, the malware has evolved with improved obfuscation techniques and new features designed to evade detection.
Originally discovered in March 2025 targeting users in Spain and Turkey, Crocodilus disguises itself as legitimate applications such as Google Chrome. The malware’s primary function is to launch overlay attacks against financial apps, harvesting credentials from unsuspecting victims. It also exploits accessibility services to capture cryptocurrency wallet seed phrases, enabling attackers to steal digital assets.
## New Distribution Tactics and Geographic Expansion
Recent campaigns have employed various distribution methods, including:
– Facebook advertisements mimicking banks and e-commerce platforms in Poland
– Fake browser updates targeting Spanish users
– Fraudulent online casino apps aimed at Turkish users
The malware has now expanded to Argentina, Brazil, India, Indonesia, and the United States, transforming into a global threat.
## Technical Advancements
Crocodilus has implemented several technical improvements:
– Enhanced obfuscation techniques to hinder analysis and detection
– A new feature allowing attackers to add contacts to victims’ devices using the command “TRU9MMRHBCRO”
– Automated seed phrase collection for cryptocurrency wallets
ThreatFabric believes the contact addition feature is designed to circumvent Google’s new Android security protections that warn users about potential scams during screen-sharing sessions with unknown contacts. By adding a contact with a name like “Bank Support,” attackers can appear legitimate when calling victims.
The evolution of Crocodilus demonstrates a concerning trend in both technical sophistication and operational scope, establishing it as a significant global cybersecurity threat.
