That’s it for Android: why it is no longer possible to store cryptocurrency on this OS
The open-source operating system has always had a lot of security issues, but it will no longer be able to protect crypto assets
28.04.2025
575
4 min
1
Cybersecurity experts have discovered a new threat for Android users, the Crocodilus trojan, which at the time of publishing this article is the most advanced software for stealing cryptocurrencies. Although research on the new virus is still ongoing and little is known about it, GetBlock AML Research publishes all available information about Crocodilus and recommendations on how to protect against the new threat.
Unknown origin
The Crocodilus trojan was discovered by cybersecurity specialists at Threat Fabric in March 2025. As of April, the virus has been widely distributed in Turkey and Spain. However, experts predict that Crocodilus will spread worldwide in the coming months.
The danger of Crocodilus lies in its tight integration with the Android operating system. Once on the device, the virus actually becomes a part of the OS, making it almost impossible to remove it without damaging the system. Crocodilus takes full control of the device and allows hackers to perform any actions with the device without the owner’s knowledge.
Another problem is that experts are still unable to identify potential authors of the virus, sources of infection, and ways of spreading the trojan. So far, experts recommend the following:
- Do not download unfamiliar apps, even from Google Play, as Crocodilus can bypass the security scanners of all major marketplaces;
- Do not click on phishing links, as in most cases they hide malware behind them;
- Do not visit, and especially do not download anything from websites with pirated software, as malicious code is embedded in them.
How Crocodilus works
Once the device is infected, Crocodilus requests access to a special capabilities service. This is necessary for the trojan to connect to the attacker’s server, through which the device is controlled, and user data is stolen. Hackers then use screen overlays (overlaying dummy windows on top of the workspace) to disguise themselves.
Crocodilus request for access to special features
When trying to open a cryptocurrency storage application, Crocodilus will hide the wallet interface and show a window that forces the user to back up private keys. If one agrees to the ruse and backs up, the wallet’s private keys are immediately sent to the hackers’ server.
Fake wallet window with a call to create a backup
Crocodilus has been taught to do something that is considered impossible in theory, remotely bypass two-factor authentication (2FA). When you open 2FA applications such as Google Authenticator, the virus turns on a screen broadcast and transmits it to the server.
Another curious feature of Crocodilus is the ability to remotely control the device, during which hackers can mute the screen and sound. This allows attackers to perform any operations on the device while the user thinks it is locked.
How to track the infection
Crocodilus is one of the most perfect viruses in terms of camouflage. However, it can be identified by some indirect signs:
- Rapid battery drain. The battery resource runs out over time, but it is the sharp decrease in the device’s operating time that can indicate the presence of a virus on the device;
- Increased data transfer. The trojan regularly communicates with the server, receiving commands from it and transmitting user data. Therefore, after infection, the amount of Internet traffic increases significantly. One of the main signs of infection is bursts of data transfer during periods when you are not using your device.
First aid in case of infection
At the first signs of Crocodilus infection, the following steps should be taken:
- Disconnect the device from the Internet;
- Remove the SIM card from the device;
- Remove the battery from the device (if possible);
- Turn off the device;
- Replace passwords and security keys via another device.
Please note that the infected device can no longer be used. Factory reset and reflashing are not guaranteed to restore security.
Useful material?
Research
A financial system is already up and running on public blockchains, with loans, analogues of U.S. Treasuries, and automated capital markets. More than $551 billion has flowed through DeFi protocols — but most of that activity has nothing to do with the real economy and everything to do with the speculative build-up of risk.
May 29, 2026
Research
Around 97% of Chinese suppliers of chemicals used to make fentanyl accept payment in cryptocurrency. The volume of such transactions continues to grow alongside the global market for synthetic drugs
May 22, 2026
Research
For the first time, the new law makes blockchain analytics an officially mandatory tool of financial oversight in the United States. Authorities will also gain the power to restrict transactions with foreign crypto services tied to money-laundering risks.
May 20, 2026
Research
Working with cryptocurrencies requires more than just new technology — it demands a complete overhaul of internal processes. We explain how the financial sector is learning to control digital assets and detect threats
May 8, 2026
Research
The scammers attempted to conceal over $90 million through complex cryptocurrency transactions. However, part of the funds was successfully traced and frozen.
May 6, 2026
Research
Just two attacks accounted for 76% of all crypto losses in 2026 and generated hundreds of millions in profit for hackers. Here’s how North Korea executes some of the most sophisticated and precise attacks in the industry.
May 1, 2026
Telegram
Twitter