Rokarolla Android Malware, How to Protect Your Banking Apps
ID: 580e9a02-9cda-59f1-b4dd-0dc136b43634
STIX ID: report--580e9a02-9cda-59f1-b4dd-0dc136b43634
Feed Name: Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa.
Rokarolla is a recently discovered Android banking- and crypto-focused Trojan distributed via fake sideloaded apps that presents fake HTML login overlays and abuses Accessibility permissions to steal credentials, SMS codes and PINs, block calls, disable Google Play Protect, rewrite wallet addresses, and exfiltrate data to resilient C2 infrastructure; users are advised to avoid sideloading apps, verify APK sources, watch for unusual permission requests, and install Android 17 if compatible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
