Rokarolla : Android Banker with Complete Device Takeover Capabilities
ID: fe64a3b6-2419-55aa-8e59-fdd59757cde0
STIX ID: report--fe64a3b6-2419-55aa-8e59-fdd59757cde0
Feed Name: Zimperium Blog
zLabs describes "Rokarolla," a sophisticated Android banking trojan distributed via malicious websites and sideloaders that targets 217 financial and cryptocurrency apps. Rokarolla abuses Accessibility services and overlays to harvest unlock credentials and banking logins, runs a keylogger, exfiltrates SMS and contacts, intercepts and blocks calls, manipulates the clipboard to swap crypto addresses, captures periodic screenshots (pseudo-VNC), disables Google Play Protect, and uses dynamic HTTPS C2 domains; the report includes technical artifacts, command listings, MITRE mappings, and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
