logo

Rokarolla : Android Banker with Complete Device Takeover Capabilities

ID: fe64a3b6-2419-55aa-8e59-fdd59757cde0

STIX ID: report--fe64a3b6-2419-55aa-8e59-fdd59757cde0

Feed Name: Zimperium Blog

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

zLabs describes "Rokarolla," a sophisticated Android banking trojan distributed via malicious websites and sideloaders that targets 217 financial and cryptocurrency apps. Rokarolla abuses Accessibility services and overlays to harvest unlock credentials and banking logins, runs a keylogger, exfiltrates SMS and contacts, intercepts and blocks calls, manipulates the clipboard to swap crypto addresses, captures periodic screenshots (pseudo-VNC), disables Google Play Protect, and uses dynamic HTTPS C2 domains; the report includes technical artifacts, command listings, MITRE mappings, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.