Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Canada Missed Chances to Inspect Titan Before Fatal Implosion

    June 19, 2026

    Metigy founder David Fairfull jailed for 9 years for misleading conduct raising $39 million and misusing $7.7m

    June 19, 2026

    Klue breach lead to Salesforce data theft, Huntress affected

    June 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Canada Missed Chances to Inspect Titan Before Fatal Implosion
    • Metigy founder David Fairfull jailed for 9 years for misleading conduct raising $39 million and misusing $7.7m
    • Klue breach lead to Salesforce data theft, Huntress affected
    • Why People Might Ditch Their Smartwatches For Something Simpler
    • Toy Story 5 Is A Surprisingly Thoughtful Critique Of Technology
    • 3 new to Paramount+ shows you need to binge-watch this weekend (June 19-21)
    • Samsung just confirmed Exynos 2700 is coming, and the Galaxy S27 could have it
    • The Download: AI bottleneck debates, and BCI trials take off
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»New Rokarolla Android malware targets 217 banking, crypto apps
    Cybersecurity

    New Rokarolla Android malware targets 217 banking, crypto apps

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 17, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    New Rokarolla Android malware targets 217 banking, crypto apps
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands.

    The malware is distributed via malicious websites purporting to provide the Google Chrome or TikTok app, and can take complete administrative control of a compromised device.

    Its capabilities include stealing lock screen credentials, contact lists, and SMS data, as well as using keyloggers to continuously record user input.

    During the installation process, the malicious app acts as a dropper and impersonates Google Play Protect, Android’s built-in anti-malware system, offering users the option to install Chrome or TikTok, which include the Rokarolla malware.

    When launched on the device, Rokarolla requests Accessibility service permissions, as well as access to notifications, SMS, and calls, researchers at mobile security company Zimperium reveal in a report today.

    The installation process
    Source: Zimperium

    Communication with the command-and-control (C2) server begins with sending a basic device profile containing details such as the phone model, installed Android version, locale, display characteristics, battery level, storage capacity, and available RAM.

    According to Zimperium, this information is used to generate a unique identifier for each victim in the Rokarolla campaign.

    Zimperium says the malware’s primary objective appears to be the theft of financial information. To achieve this, it checks the infected device against a list of 217 targeted applications and then downloads the phishing payload corresponding to any matching apps.

    When the victim opens an app on the list, Rokarolla displays a fake login overlay to steal login credentials, credit card information, and other financial data.

    Financial data theft process
    Source: Zimperium

    The use of overlays extends beyond data theft, though. The malware also relies on this method to capture the lock-screen PIN/pattern and operate the device even when it is locked.

    Additionally, overlays are used to hide the malware activity and block user interaction by displaying fake installation screens when needed.

    PIN overlay (left) and fake installation overlay (right)
    Source: Zimperium

    Additional evasion tactics include disabling Google Play Protect, hiding the application icon from the app drawer, silencing audio and vibration, and keeping the screen awake indefinitely.

    Zimperium created a GitHub repository with all 137 commands available to Rokarolla. Some of the data-theft commands include:

    • Steal SMS messages
    • Extract contact information and WhatsApp contacts
    • Capture keystrokes
    • Record on-screen content via UI logging
    • Copy and manipulate the clipboard contents
    • Block incoming calls and bank fraud alerts
    • Periodically take screenshots and upload them with timestamps

    The combination of these capabilities gives Rokarolla operators near-complete administrative control over an infected Android device, enabling them to commit advanced financial fraud.

    Zimperium did not find the malware on Google Play, the official repository for Android apps. Users are recommended to avoid downloading APK files outside Google Play unless they explicitly trust the publisher.

    Furthermore, users should exercise caution when granting Accessibility permissions, as they can be abused to bypass standard Android security protections and obtain elevated capabilities to interact with the user interface or approve system prompts, actions frequently sought by Android malware.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Android apps Banking Crypto malware Rokarolla targets
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Klue breach lead to Salesforce data theft, Huntress affected

    June 19, 2026

    5 reasons I’m using Android Auto instead of my car’s own infotainment system – and can’t go back

    June 19, 2026

    June 2026 Windows updates break Recycle Bin prompts

    June 19, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views

    Nothing CEO says phone prices are going to keep going up

    June 12, 20262 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Canada Missed Chances to Inspect Titan Before Fatal Implosion
    • Metigy founder David Fairfull jailed for 9 years for misleading conduct raising $39 million and misusing $7.7m
    • Klue breach lead to Salesforce data theft, Huntress affected
    • Why People Might Ditch Their Smartwatches For Something Simpler
    • Toy Story 5 Is A Surprisingly Thoughtful Critique Of Technology

    Canada Missed Chances to Inspect Titan Before Fatal Implosion

    June 19, 2026

    Metigy founder David Fairfull jailed for 9 years for misleading conduct raising $39 million and misusing $7.7m

    June 19, 2026

    Klue breach lead to Salesforce data theft, Huntress affected

    June 19, 2026

    Why People Might Ditch Their Smartwatches For Something Simpler

    June 19, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.