Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Facebook X (Twitter) Instagram
Wednesday, June 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Cyber Security

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

Team-CWDBy Team-CWDJune 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly discovered Android banking trojan has been observed going beyond draining accounts, seizing near-total control of a phone and cutting victims off from their banks so fraud can run undetected.

Named Rokarolla after its command-and-control (C2) servers, the malware was detailed by zLabs, the research arm of mobile security firm Zimperium, which found it targeting 217 banking and cryptocurrency apps through a toolkit of 137 commands.

It spreads through malicious sites that masquerade as TikTok or Google Chrome, using a dropper that poses as Google Play Protect to slip a second-stage payload past Android’s defenses and onto the device.

“The Rokarolla trojan marks a shift from data theft to victim isolation,” explained Jason Soroko, senior fellow at certificate-management firm Sectigo, who described Rokarolla turning the phone into a weapon against its owner.

Read more: Android Malware Targets Banking Users Through Discord Channels

To keep that grip, Rokarolla makes itself the device’s default handler for calls and texts. It can block incoming calls and read or send SMS messages, letting it swallow the one-time codes and fraud alerts a bank would normally use to flag a suspect transfer.

It also mutes the phone’s audio and vibration to hide alert tones, hides its own icon from the app drawer and forces the screen to stay awake so its hidden activity is never interrupted.

Fake Screens and Stolen Logins

The theft leans on Accessibility Services, the Android feature for assistive apps, which Rokarolla abuses to read the screen and drive the interface. From there it harvests:

  • Banking and crypto logins, captured by fake overlay screens

  • Lock screen PINs, patterns and passwords

  • Keystrokes and on-screen text

  • SMS messages, including bank one-time codes

  • WhatsApp contacts, scraped from the display

When a victim opens a targeted app, the malware drops a convincing fake login page, fetched from its server, over the real one.

It can also rewrite the clipboard on the fly, swapping in an attacker’s cryptocurrency wallet address when the victim copies their own.

For surveillance, rather than streaming the screen live, Rokarolla quietly takes timestamped screenshots and exfiltrates them one by one. It also tries to disable Google Play Protect to keep itself hidden.

The campaign coincides with a substantial increase in mobile threats. Randolph Barr, CISO at API security firm Cequence Security, noted, “Android continues to face banking trojans and data-leaking SDKs,” citing tens of millions of mobile malware incidents blocked in 2024 alone.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFBI Warns Courier Cash Pickups Are Driving Crypto Scams
Next Article WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
Team-CWD
  • Website

Related Posts

Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Cyber Security

Trump Issues Executive Order to Fast-Track Post-Quantum Migration

June 23, 2026
Cyber Security

Microsoft Attributes Mastra AI Supply Chain Attack to North Korea

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Your information is on the dark web. What happens next?

January 13, 2026

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.