Crocodilus
MITRE ATT&CK: S9004 View on attack.mitre.org
Aliases: Crocodilus
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- android
- Related IoCs
- 5 (5 malicious)
- Last IoC activity
- 2026-08-26 15:49:46
- Profile updated
- 2026-07-07 14:05:33
Targeted industries: financial-services
Targeted regions: country_code:tr country_code:pl country_code:ar country_code:br country_code:es country_code:us country_code:id country_code:in
Context
Crocodilus is an Android banking Trojan that was discovered in March 2025. Crocodilus targeted users worldwide, including Turkey, Poland, Argentina, Brazil, Spain, the United States, Indonesia and India. Crocodilus has been customized based on the target location. For example, Crocodilus mimicked major Turkish and Spanish banks for users in Turkey and Spain, while users in Poland saw Facebook advertisements that promoted Crocodilus to claim bonus points.
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to Crocodilus (S9004). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | rentvillcr.homes | 2026-08-26 | 1 |
| hostname | mastercardkeys.world | 2026-08-03 | 1 |
| file sample | fb046b7d0e385ba7ad15b766086cd48b4b099e612d8dd0a460da2385dd31e09e | 2026-08-02 | 1 |
| file sample | 6d55d90d021b0980528f56d040e78fa7b85a96f5c244e23f330f24c8e80c1cb2 | 2026-08-02 | 1 |
| hostname | rentvillcr.online | 2026-07-26 | 1 |
Malware & tools used
- Financial Theft (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Masquerading (attack-pattern)
- Call Control (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Video Capture (attack-pattern)
- SMS Control (attack-pattern)
- User Evasion (attack-pattern)
- Uninstall Malicious Application (attack-pattern)
- Web Protocols (attack-pattern)
- Input Injection (attack-pattern)
- SMS Messages (attack-pattern)
- Screen Capture (attack-pattern)
- Contact List (attack-pattern)
- Abuse Accessibility Features (attack-pattern)
- Device Administrator Permissions (attack-pattern)
- Software Packing (attack-pattern)
- Software Discovery (attack-pattern)
- Prevent Application Removal (attack-pattern)
- Keylogging (attack-pattern)
- GUI Input Capture (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Crocodilus (report)
- threatfabric.com — Crocodilus Mobile Malware Evolving Fast Going Global (report)
- medium.com — Crocodilus In The Wild Mapping The Campaign In Poland 15D3078Eb954 (report)
- medium.com — Bombardino Crocodilo In Poland Analysis Of Iko Lokaty Mobile Malware Campaign 502Bd74947F3 (report)
- threatfabric.com — Exposing Crocodilus New Device Takeover Malware Targeting Android Devices (report)
- shindan.io — Crocodilus A Deep Dive Into Its Structure And Capabilities (report)
- MITRE ATT&CK — S9004 (report)