03 Apr 2025

light mode

New Malware Crocodilus Bypasses Android Security to Steal Crypto

“Crocodilus” mobile virus steals cryptocurrencies and sensitive data. - The Coinomist

New Android malware Crocodilus bypasses built-in security measures and steals sensitive data through fake interfaces, including bank accounts to crypto wallets.

On this page

Security researchers at ThreatFabric uncovered the Trojan malware during a broader investigation into mobile threats. 

Crocodilus is highly sophisticated, using advanced techniques to evade detection, steal confidential information and digital assets, and remotely control infected devices. 

The virus stands out for its distinct set of features. It: 

  • generates fake screens that overlay legitimate apps,
  • secretly takes control of the device,
  • and gathers data using built-in logging tools. 

A key component of its functionality is the use of Accessibility Logger technology, which records all user activity, including password entries and the display of one-time codes.

Related: Crypto Heist 101: How Hackers Steal Millions in Crypto

To trick users, Crocodilus actively uses social engineering. For example, when opening a banking or crypto app, the malware displays a fake warning, claiming the user must back up their wallet key within 12 hours or risk losing access. This tactic pressures users into entering highly sensitive information, which the malware then records and sends to its operators.

Crocodilus is also able to make any remote access “hidden” – displaying a black screen overlay on top of all the activities, effectively hiding the actions performed by the malware. As a part of this “hidden” activity the malware also mutes the sound on the infected device to ensure fraudulent activities remain unnoticed by victim,

said researchers at ThreatFabric.

In addition, the malware can also intercept data from apps that use two-factor authentication, including Google Authenticator. On command, Crocodilus captures screenshots showing one-time passcodes (OTPs), giving attackers immediate access to accounts and financial transactions.

Infection Methods and User Impact

ThreatFabric researchers report that Crocodilus infections most often begin with the installation of seemingly legitimate apps that later download the malware, allowing it to bypass Android’s standard security protections. Once installed, the Trojan malware requests access to Accessibility Services, giving it control over the device and the ability to receive real-time commands from a remote server.

Initial campaigns observed by our Mobile Threat Intelligence team show targets primarily in Spain and Turkey, along with several cryptocurrency wallets. We expect this scope to broaden globally as the malware evolves,

the security experts noted.

Users whose devices fall under the control of Crocodilus face serious risks. Specifically, attackers can: 

  • carry out unauthorized transactions,
  • completely drain bank and crypto accounts,
  • and use the infected device to launch additional attacks. 

Furthermore, current detection methods often fail to identify threats like this in the early stages.

Experts strongly recommend a comprehensive approach to mobile security. Users should pay close attention to app behavior and carefully review any requests for special permissions. At the same time, companies, including mobile OS developers, should implement multi-layered defense systems to keep pace with evolving threats.

Related: WhiteBIT’s Cybersecurity Tips

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Why Is $BTC Dropping? Trump’s Tariff Shock and the Big Tech Meltdown

Why Is $BTC Dropping? Trump’s Tariff Shock and the Big Tech Meltdown

The escalating U.S.–China trade war and a tech stock downturn have created a perfect storm. Crypto investors are moving to cash as BTC breaks through key support levels.

Vlad Vovk
Warren Demands SEC Release Information on WLFI, Investigating Trump Ties

Warren Demands SEC Release Information on WLFI, Investigating Trump Ties

Senator Warren and Congresswoman Waters have called on the SEC to release information about WLFI, a crypto firm linked to the Trump family, raising concerns over the impartiality of crypto industry regulation.

Dmytro Psevdonimenko
Neuralink Launches Human Trials for Brain Implants

Neuralink Launches Human Trials for Brain Implants

Neuralink has begun clinical trials of its brain-computer technology on individuals with disabilities. Participants will receive compensation for all expenses, including transportation.

Vlad Vovk
PayPal Adds Solana (SOL) and Chainlink (LINK) for U.S. Customers

PayPal Adds Solana (SOL) and Chainlink (LINK) for U.S. Customers

PayPal added Solana (SOL) and Chainlink (LINK) support for U.S. customers and U.S. territories, based on the company’s FAQ page.

Anahit Avetisyan
Sam Altman, ChatGPT, and the AI Spark That Lit Up Crypto

Sam Altman, ChatGPT, and the AI Spark That Lit Up Crypto

At the end of 2022, a public beta of an AI-powered product quietly launched. It looked like nothing more than a simple chat window. However, it turned out to be a global sensation.

Elina Moskovchuk
Hot Crypto Discussions on X Today: VPN Use, Trump Tariffs, and More

Hot Crypto Discussions on X Today: VPN Use, Trump Tariffs, and More

The crypto market faces a blow as Trump announces 10% tariffs on all countries, fueling economic uncertainty that impacts the financial sector.

Anahit Avetisyan
Hot on X (Twitter) Today: Binance Boycott, McCormack vs. Wright Case, & More

Hot on X (Twitter) Today: Binance Boycott, McCormack vs. Wright Case, & More

A “Boycott Binance” movement is trending on X/Twitter after multiple altcoins plunged on the exchange within minutes on April 1.

Anahit Avetisyan
What Are Assets? Differences Between Coins and Tokens

What Are Assets? Differences Between Coins and Tokens

Discover the meaning of assets in finance and crypto, and learn the key differences between coins and tokens to make informed investment decisions.

The Coinomist
What Is a Margin Call? An Essential Guide

What Is a Margin Call? An Essential Guide

A comprehensive guide to understanding margin calls in trading. Learn what triggers them, how they work, their risks, and strategies to manage or avoid them

The Coinomist
What Happens When Bitcoin Runs Out? Predictions and Strategies

What Happens When Bitcoin Runs Out? Predictions and Strategies

Explore what happens when Bitcoin reaches its 21 million supply cap. Learn how the shift from block rewards to transaction fees could impact miners, investors, and the entire ecosystem.

The Coinomist
What Does HODL Mean? Lessons for New Traders

What Does HODL Mean? Lessons for New Traders

Learn the meaning behind HODL and its significance in crypto trading. Understand its origins, the psychology behind holding on, and how HODLing can shape your long-term investment strategy.

The Coinomist
How to Scale a Crypto Exchange and Attract More Users Globally

How to Scale a Crypto Exchange and Attract More Users Globally

Imagine you’ve built your own crypto exchange, and now it’s time to scale. You’ll need high-speed infrastructure, deep liquidity, and compliance.

Vlad Vovk
The Top Cryptocurrency Scams to Watch Out for in 2025

The Top Cryptocurrency Scams to Watch Out for in 2025

AI, fake exchanges, celebrity deepfakes, and old tricks repackaged in new forms. Here’s a look at the cryptocurrency scams gaining traction in 2025 and how to avoid losing everything to fraudsters.

Vlad Vovk
Arthur Hayes Challenges Fed Independence in His New Essay “The BBC”

Arthur Hayes Challenges Fed Independence in His New Essay “The BBC”

In his latest essay “The BBC,” Arthur Hayes examines the emotional pressures on the Federal Reserve and the monetary policy challenges that could lead to increased liquidity in the crypto market.

Dmytro Psevdonimenko
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
MORE
Dubai Lets You Rent Homes and Cars With Bitcoin. Here’s What to Know

Dubai Lets You Rent Homes and Cars With Bitcoin. Here’s What to Know

Now, you can rent in Dubai with crypto, signing rental agreements using BTC, altcoins, or USDT for both short-term vacations and long-term stays as an expat.

Yara Zornell
Why Lisbon is Now Emerging as The Newest World’s Crypto Capital

Why Lisbon is Now Emerging as The Newest World’s Crypto Capital

Imagine a city of hills, narrow cobblestone streets, and fado music drifting from cozy bars. This is Lisbon, the capital of Portugal, now rapidly transforming into a modern crypto city.

Iaroslava Kramarenko
MORE