Rokarolla Trojan Combines Banking Fraud With Device Surveillance
ID: a3d1a88d-77e5-5e8c-b059-66acb191b69e
STIX ID: report--a3d1a88d-77e5-5e8c-b059-66acb191b69e
Feed Name: Infosecurity Magazine (News)
Threat Score
Rokarolla is an Android banking trojan observed by zLabs that targets 217 banking and cryptocurrency apps using a 137-command toolkit. It spreads via malicious sites and a dropper impersonating Google Play Protect, abuses Accessibility Services to display fake overlays, steal logins and OTPs, rewrite clipboards, take screenshots, disable Play Protect, and isolate victims by blocking calls and muting alerts to facilitate undetected fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
