ATT&CKSoftwareCrocodilus

Crocodilus

S9004

Malware.View on attack.mitre.org

About this malware

Crocodilus is an Android banking Trojan that was discovered in March 2025. Crocodilus targeted users worldwide, including Turkey, Poland, Argentina, Brazil, Spain, the United States, Indonesia and India. Crocodilus has been customized based on the target location. For example, Crocodilus mimicked major Turkish and Spanish banks for users in Turkey and Spain, while users in Poland saw Facebook advertisements that promoted Crocodilus to claim bonus points.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1657
Financial Theft

Crocodilus has stolen cryptocurrency wallet details from victim devices.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. ThreatFabric_Crocodilus_June2025 Open source
    ThreatFabric. (2025, June 3). Crocodilus Mobile Malware: Evolving Fast, Going Global. Retrieved November 24, 2025.
  2. ThreatFabric_Crocodilus_March2025 Open source
    ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.