Alert: New Android Malware “Crocodilus” Targets Crypto Wallets with Deceptive Tactics

Alert: New Android Malware

# New Android Malware “Crocodilus” Targets Cryptocurrency Wallets

A sophisticated new Android malware called Crocodilus has emerged, employing clever social engineering tactics to steal cryptocurrency wallet seed phrases. Security researchers at ThreatFabric have identified this banking malware, which comes with advanced capabilities to control infected devices and harvest sensitive data.

## How Crocodilus Works

The malware uses a proprietary dropper that effectively bypasses Android 13+ security protections, including Play Protect and Accessibility Service restrictions. What makes Crocodilus particularly dangerous is its social engineering approach—it displays a fake warning message urging users to “back up their wallet key in the settings within 12 hours” or risk losing access to their funds.

When victims navigate to their seed phrase following these instructions, the malware captures the text through its Accessibility Logger, giving attackers complete control over the cryptocurrency wallet.

## Technical Capabilities

Crocodilus abuses Android’s Accessibility Service—designed to assist users with disabilities—to:
– Access screen content
– Perform navigation gestures
– Monitor app launches
– Display fake overlays to steal credentials

The malware supports 23 different commands, including:
– Enabling call forwarding
– Sending SMS messages
– Requesting device admin privileges
– Activating screen overlays
– Making itself the default SMS manager

It also functions as a remote access trojan (RAT), allowing attackers to:
– Control the device remotely
– Capture screenshots of Google Authenticator for 2FA codes
– Display black screen overlays to hide malicious activity

## Current Targets and Origin

Currently, Crocodilus primarily targets users in Turkey and Spain, focusing on banking and cryptocurrency apps in these regions. Debug messages suggest the malware is of Turkish origin, though its targeting could expand in the future.

## Protection Recommendations

To protect against this threat, Android users should:
– Avoid downloading APKs from outside Google Play
– Ensure Play Protect remains active on their devices
– Be suspicious of unexpected warnings about cryptocurrency wallets

Share This Article