logo

Rokarolla Android trojan targets banking and crypto users, enables device takeover

ID: d2eb0a09-08e8-58ec-a7b8-49248c5d1e5d

STIX ID: report--d2eb0a09-08e8-58ec-a7b8-49248c5d1e5d

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Sinisa Markovic

...
...

Zimperium discovered Rokarolla, an Android banking trojan distributed via malicious websites impersonating legitimate apps that targets 217 banking and cryptocurrency applications; it abuses Accessibility Services and permissions to deploy phishing overlays, exfiltrate SMS/contacts/credentials, perform keylogging and clipboard manipulation, capture screenshots, block calls, mute device audio, and receive 137 remote commands from C2 infrastructure—Zimperium published IoCs and a MITRE ATT&CK mapping.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.