Newzchain
Cyber Security·News

New Android Malware "Crocodilus" Poses Serious Threat to Cryptocurrency Users

Harshajit Sarmah
Harshajit Sarmah·Mar 31, 2025·2 min read
Android smartphone with a warning overlay about backing up a crypto wallet, representing the Crocodilus malware attack

A newly identified Android malware, dubbed Crocodilus, is raising alarms among cybersecurity experts due to its sophisticated methods for stealing sensitive cryptocurrency wallet credentials through social engineering tactics.

Initially reported in Spain and Turkey, the malware's advanced capabilities suggest a potential for widespread attacks across various regions.

Crocodilus is distributed via a proprietary dropper that effectively bypasses the security protections of Android 13 and later versions, allowing it to evade detection by Google’s Play Protect system.

Once installed on a device, Crocodilus requests access to the Accessibility Service, a feature designed to assist users with disabilities.

However, this access allows the malware to monitor screen content, simulate user gestures, and interact with applications covertly. This manipulation is particularly dangerous as it enables the malware to execute commands without the user's knowledge.

Now, what sets Crocodilus apart from other malware is its use of a highly convincing overlay screen that warns users to back up their wallet key within 12 hours or risk losing access.

This prompt is designed to lead victims directly to their crypto wallet’s seed phrase, which the malware logs using an Accessibility Logger. With this information, attackers can gain full control over the victim’s cryptocurrency wallet.

Newsletter

The corridor, every morning.

Funding rounds and cross-border capital moves, one email, five minutes.

In addition to targeting seed phrases, Crocodilus can also load fake overlays on banking or cryptocurrency applications to intercept user credentials.

The malware's bot component supports an array of 23 commands, including:

These features enable attackers not only to steal sensitive information but also to manipulate devices in ways that can remain undetected by users.

Furthermore, while executing these operations, Crocodilus can activate a black screen overlay and mute the device, creating an illusion that it is locked or inactive. This method of concealment poses significant risks as it allows malicious activities to occur without arousing suspicion.

The emergence of Crocodilus is reminiscent of previous sophisticated Android malware attacks:

The emergence of Crocodilus highlights an alarming trend in mobile malware targeting financial assets. As cybercriminals continue to refine their techniques, users must remain vigilant. Experts recommend avoiding downloads from third-party app stores, regularly updating devices, and being cautious with accessibility permissions.


Edited by Harshajit Sarmah

More in Cyber Security