logo

New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps

ID: 39f2b4a7-342b-5494-90df-2b71fb92c01f

STIX ID: report--39f2b4a7-342b-5494-90df-2b71fb92c01f

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Pierluigi Paganini

...
...

Rokarolla is a sophisticated Android banking trojan distributed via malicious websites masquerading as popular apps and a Google Play Protect–style dropper; once granted Accessibility permissions it deploys overlays and fake login/lock screens, intercepts SMS and calls, hijacks clipboards, captures screenshots and keystrokes, disables Play Protect, and targets 217 banking and crypto apps — Zimperium’s report includes C2 domains, APK hashes and mitigation guidance (only install from Play, don't grant Accessibility to unknown apps, avoid default SMS/call handler).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.