Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/News/Crocodilus malware takes Android users’ crypto wallet keys
News

Crocodilus malware takes Android users’ crypto wallet keys

Robert Haba
Apr 1, 20253 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
crocodilus novo malware
0%
Share on XFacebookBluesky
Follow on Google
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Using a warning to backup the key to prevent losing access, a recently identified Android malware known as Crocodilus deceives users into entering the seed phrase for the bitcoin wallet.

Despite being a recent banking malware, Crocodilus has fully functional capabilities to remotely control, take over the device, and collect data.

According to researchers at the fraud prevention firm ThreatFabric, the malware is disseminated by a custom dropper that gets around security measures in Android 13 and later.

The dropper circumvents Accessibility Service limitations and installs the virus without activating Play Protect.

Crocodilus is unique because it uses social engineering to force victims to divulge their crypto-wallet seed phrase.

A screen overlay alerting users to “back up their wallet key in the settings within 12 hours” or risk losing your wallet is how it accomplishes this.

You May Also Like
Recommended
1

Fake ChatGPT custom GPT used to spread malware via Google ads

Fake ChatGPT custom GPT used to spread malware via Google ads
2

Huawei Kirin 9050 Pro chipset: full specs and what’s new

kirin 9050
3

The 5 biggest phone launches to watch in September 2026

semptember 2026 phones

“This social engineering trick guides the victim to navigate to their seed phrase (wallet key), allowing Crocodilus to harvest the text using its Accessibility Logger,” ThreatFabric explains.

“With this information, attackers can seize full control of the wallet and drain it completely,” the researchers say.

Crocodilus was seen to target customers in Spain and Turkey, including bank accounts from those two nations, during its initial operations. Based on the debug messages, it seems that the infection originated in Turkey.

Although the exact mechanism of the first infection is unknown, users are usually duped into downloading droppers by malicious websites, phony SMS or social media advertisements, and third-party app shops.

When Crocodilus is launched, it has access to Accessibility Services, which are typically designated for helping individuals with disabilities. These services allow Crocodilus to make navigation motions, monitor for app launches, and unlock screen content.

crocodilus malware

Crocodilus puts a phony overlay over the legitimate app when the victim accesses a targeted banking or cryptocurrency app in order to obtain the victim’s login information.

The bot component of the malware supports a set of 23 commands that it can execute on the device, including:

  • Enable call forwarding
  • Launch a specific application
  • Post a push notification
  • Send SMS to all contacts or a specified number
  • Get SMS messages
  • Request Device Admin privileges
  • Enable a black overlay
  • Enable/disable sound
  • Lock screen
  • Make itself the default SMS manager

Additionally, the malware has remote access trojan (RAT) capabilities that let its operators swipe, tap, and browse the user interface, among other things.

To collect one-time password codes used for two-factor authentication account protection, a specific RAT command is also available to snap a screenshot of the Google Authenticator application.

To conceal the activity from the victim and give the impression that the device is locked, Crocodilus operators can mute the device and activate a black screen overlay while doing these tasks.

Crocodilus may soon expand its activities and add more apps to its target list, even if it currently seems to be targeting only Spain and Turkey.

It is recommended that Android users make sure Play Protect is constantly enabled on their devices and refrain from downloading APKs from sources other than Google Play.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#android#app#crocodilus#crypto#cybersecurity#keys#malware#security#wallet
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Next Story in News

Fake ChatGPT custom GPT used to spread malware via Google ads

Cybersecurity researchers at Huntress have uncovered a campaign where hackers built a custom ChatGPT model to trick people into launching malware on their own PCs, turning one of OpenAI's own features against its users. The campaign starts on Google search. Anyone searching for “chatgpt” might click a sponsored ad at the top of the results […]

→

Latest Stories

Exclusive Pixel 11a renders reveal design, colors, and a Tensor G6 jump01

Exclusive Pixel 11a renders reveal design, colors, and a Tensor G6 jump

02

Fake ChatGPT custom GPT used to spread malware via Google ads

03

6 Best AI Video Generators for Creators and Teams in 2026

04

Android 17 QPR2 Beta 6.1 fixes a Pixel 11 Pro Fold Face Unlock issue

Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Recommended stories

Continue reading

More from this category →
Fake ChatGPT custom GPT used to spread malware via Google ads
NewsOct 2, 2026

Fake ChatGPT custom GPT used to spread malware via Google ads

Cybersecurity researchers at Huntress have uncovered a campaign where hackers built a custom ChatGPT model to trick people into launching malware on their own PCs, turning one of OpenAI's own features against its users. The campaign starts on Google search. Anyone searching for “chatgpt” might click a sponsored ad at the top of the results […]

By Robert Haba
kirin 9050
NewsSep 11, 2026

Huawei Kirin 9050 Pro chipset: full specs and what’s new

Huawei has released its new high-performance Kirin 9050 Pro chipset, and details about the silicon's architecture are now available across CPU, GPU, NPU, modem, security, and cooling. CPU, GPU, and NPU upgrades The chip's LinxiCore CPU supports simultaneous multi-threading and delivers a 24% gain in peak single-core performance alongside a 52% gain in multi-core concurrent […]

By Robert Haba
semptember 2026 phones
NewsSep 8, 2026

The 5 biggest phone launches to watch in September 2026

September is usually iPhone season, but this year several Android brands are packing their very best hardware into the same four-week stretch, aiming to steal some of the spotlight. More than 20 phones are expected to launch this month alone, and here's a rundown of five of the biggest phone launches on the calendar for […]

By Luiza Mosneagu
NewsSep 4, 2026

Google’s Scam Detection could be coming to Xiaomi phones, teardown suggests

Google's Scam Detection feature could be coming to Xiaomi phones next, according to a new APK teardown by Android Authority. The AI-powered scam-call warning tool debuted first on Pixel devices, has since expanded to Samsung's Galaxy S26 series, and has shown signs of heading to vivo phones as well, and Android Authority now says it's […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.