TF-MAL-apk.crocodilus
📛 Threat Title
Malware family: Crocodilus
Description
ThreatFox malware family `apk.crocodilus`. Printable name: Crocodilus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.crocodilus
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.crocodilus
IOC database
- Type
- domain
- Value
apk.crocodilus- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.crocodilus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.crocodilus
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Crocodilus is an Android banking Trojan that was discovered in March 2025. Crocodilus targeted users worldwide, including Turkey, Poland, Argentina, Brazil, Spain, the United States, Indonesia and India.
-
web:cybersecsentinel.com
Crocodilus is a top-tier mobile threat with a modular and adaptive architecture. Its ability to bypass Android 13+ security, steal cryptocurrency wallet data, impersonate legitimate apps, and support vishing makes it extremely dangerous.
-
web:cybersecuritynews.com
A sophisticated new Android banking Trojan named Crocodilus has emerged as a significant global threat, demonstrating advanced device-takeover capabilities that grant cybercriminals unprecedented control over infected smartphones. First discovered in March 2025, this malware has rapidly evolved from localized test campaigns to a worldwide operation targeting financial institutions and ...
-
web:imtr.net
The provided context is very limited, containing only the title, author, publication date, and links related to an article about " Crocodilus Mobile Malware ," but it lacks the actual technical content required to populate the requested detailed summary structure ( Malware information, TTPs, MITRE ATT&CK mappings, IOCs, etc.).
-
web:malpedia.caad.fkie.fraunhofer.de
Crocodilus Propose Change According to ThreatFabric, this malware offers remote control, black screen overlays, and advanced data harvesting via accessibility logging.
-
web:thehackernews.com
Cybersecurity researchers have discovered a new Android banking malware called Crocodilus that's primarily designed to target users in Spain and Turkey. " Crocodilus enters the scene not as a simple clone, but as a fully-fledged threat from the outset, equipped with modern techniques such as remote control, black screen overlays, and advanced data harvesting via accessibility logging ...
-
web:www.broadcom.com
A new variant of the Crocodilus mobile malware has been spread in recent campaigns targeting users in Europe and South America. Crocodilus is a banking malware family discovered earlier this year that has extensive remote control and infostealing functionalities including remote access, data theft, keylogging and arbitrary command execution.
-
web:www.linkedin.com
Crocodilus operates as a device-takeover malware that infects Android devices through social engineering and then exploits Accessibility features to gain near-total control. Understanding its ...
-
web:www.secureblink.com
Crocodilus Android banking Trojan stole $2.8M via crypto wallet overlays & RAT hijacking, infecting 1,200+ devices. Mitigation steps inside
-
web:www.threatfabric.com
Discover the latest developments on Crocodilus , a sophisticated Android Trojan targeting banking apps and crypto wallets across the globe.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.