logo

New Rokarolla Android malware targets 217 banking, crypto apps

ID: 0f2851a4-a0e4-5a6b-9ceb-36e7d2757e27

STIX ID: report--0f2851a4-a0e4-5a6b-9ceb-36e7d2757e27

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Bill Toulas

...
...

A Zimperium analysis describes Rokarolla, a sophisticated Android banking trojan distributed through malicious websites offering sideloaded Chrome/TikTok APKs; it requests Accessibility and other permissions, disables protections, and uses overlays, keylogging, SMS/contact theft and 137 commands to steal credentials and take near-complete control of infected devices—targeting 217 banking and cryptocurrency apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.