logo

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds

ID: d7407f17-058f-5368-909a-2d42d3e14dd8

STIX ID: report--d7407f17-058f-5368-909a-2d42d3e14dd8

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

Zimperium's zLabs documented 'Rokarolla', a sophisticated Android banking trojan distributed via fake app websites and a dropper disguised as Google Play Protect; it abuses Accessibility permissions to disable Play Protect, install payloads, capture lock-screen credentials, present HTML overlays to harvest logins and card data, intercept and send SMS (including OTPs), rewrite the clipboard to hijack crypto payments, take stealthy screenshots, and supports 137 remote commands with multiple fallback C2s—indicators and detections are published by Zimperium.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.