Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rokarolla Trojan Threatens Over 200 Banking Apps

Rokarolla Trojan Threatens Over 200 Banking Apps

Posted on June 18, 2026 By CWS

Android users are being alerted by mobile security company Zimperium about a new threat named Rokarolla, a banking trojan capable of compromising over 200 cryptocurrency and banking applications. This malware represents a significant risk to users by targeting a wide array of financial platforms.

Malware Distribution and Deceptive Tactics

Rokarolla is being spread through malicious websites where it masquerades as popular applications like Chrome and TikTok. This deceptive strategy involves tricking users into downloading the malware, which then impersonates legitimate services such as Google Play Protect to deliver its harmful payload.

Capabilities and Methods of Rokarolla

Once installed on a device, Rokarolla aggressively seeks permissions, enabling it to gain control over the device even when it’s locked by accessing lockscreen credentials such as PINs, patterns, or passwords. The trojan employs screen overlays to extract credentials from 217 targeted banking and cryptocurrency apps.

In addition to these capabilities, Rokarolla misuses Accessibility Services to harvest WhatsApp contact details and can intercept SMS messages and phone calls. Its keylogging functionality records every keystroke, while it also manipulates clipboard contents to swap out cryptocurrency addresses with those controlled by attackers.

Advanced Evasion Techniques

Rokarolla is designed with sophisticated evasion techniques to avoid detection. It initially conceals its icon from the app drawer to prevent visual discovery. Further, it can mute all device sounds and vibrations, thus ensuring its activities remain undetected. This includes suppressing security alerts and incoming verification calls, which might otherwise alert users to fraudulent transactions.

The malware’s ability to systematically capture and compress screenshots into PNG format, complete with timestamps, adds another layer of threat, allowing attackers to exfiltrate sensitive visual data quietly.

Conclusion and Implications

The emergence of Rokarolla highlights significant vulnerabilities within mobile security frameworks, particularly concerning financial applications. Users are urged to remain vigilant and safeguard their devices by avoiding downloads from untrusted sources. As the landscape of mobile threats continues to evolve, the importance of robust security measures becomes increasingly paramount.

Security Week News Tags:Android security, banking apps, Cryptocurrency, Cybersecurity, Keylogger, Malware, mobile threats, Phishing, Rokarolla, Trojan, Zimperium

Post navigation

Previous Post: Microsoft Unveils New Windows Malware Threat
Next Post: Critical Fixes in Firefox 152 for Remote Code Threats

Related Posts

CISA Alerts on Active Exploitation of Major Software Vulnerabilities CISA Alerts on Active Exploitation of Major Software Vulnerabilities Security Week News
Spanish Crackdown on Anonymous Fénix Hackers Spanish Crackdown on Anonymous Fénix Hackers Security Week News
SSHStalker Botnet Exploits Legacy Linux Vulnerabilities SSHStalker Botnet Exploits Legacy Linux Vulnerabilities Security Week News
Trump’s AI Cybersecurity Order: Industry Insights Trump’s AI Cybersecurity Order: Industry Insights Security Week News
Flare Raises  Million for Threat Exposure Management Platform Flare Raises $30 Million for Threat Exposure Management Platform Security Week News
Supply Chain Attack Hits Checkmarx Jenkins Plugin Supply Chain Attack Hits Checkmarx Jenkins Plugin Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark