Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rokarolla Malware Targets Banking Apps with Advanced Tactics

Rokarolla Malware Targets Banking Apps with Advanced Tactics

Posted on June 16, 2026 By CWS

Security researchers have uncovered a new Android malware, named Rokarolla, that poses a significant threat to mobile banking and cryptocurrency applications. This advanced trojan, documented by Zimperium’s zLabs, targets 217 apps and executes 137 remote commands, granting near-total control over infected devices.

How Rokarolla Operates

Rokarolla infiltrates devices through malicious websites that imitate popular applications like TikTok and Chrome. Initially, users are tricked into downloading a dropper disguised as Google Play Protect. This dropper facilitates the installation of the malware’s payload and gains Accessibility access, which is critical for disabling security features such as Google Play Protect.

Upon activation, Rokarolla employs overlay attacks to deceive users. It fetches fake HTML login pages from its server, which are stored locally. When a user opens a legitimate banking or cryptocurrency app, the malware overlays a counterfeit page to capture sensitive information, including login credentials and card details.

Comprehensive Data Theft

Rokarolla employs sophisticated techniques to intercept a wide array of user data. It reads SMS messages and can send them, enabling the interception of one-time passcodes used for secure transactions. By setting itself as the default messaging app, it can block incoming calls, preventing users from receiving alerts from their banks.

The malware includes keylogging and screen logging capabilities, recording everything the user types and sees. It also alters the clipboard contents, replacing copied cryptocurrency wallet addresses with those controlled by the attackers, leading to misdirected transfers.

Cloaked Surveillance and Persistence

For surveillance, Rokarolla forgoes traditional methods like MediaProjection to avoid detection. Instead, it captures and compresses screenshots via Accessibility, sending them to its operators discreetly. This method is less conspicuous than live screen casting used by other malware.

Rokarolla’s resilience is bolstered by multiple fallback command-and-control (C2) domains, allowing it to remain operational even if some servers are disabled. Its extensive command set surpasses that of previous malware like the HOOK trojan, underscoring its threat level.

Defensive Measures and Future Outlook

Currently, there is no specific patch to mitigate Rokarolla, as it exploits user behavior rather than software vulnerabilities. Users are advised to install apps solely from trusted sources like Google Play, keep Play Protect active, and scrutinize any request for Accessibility permissions.

Zimperium’s products can detect Rokarolla, and indicators of compromise are available in their GitHub repository. While the malware’s origins remain unidentified, its design clearly aims to bypass standard security measures, highlighting the need for vigilance and robust mobile security practices.

The Hacker News Tags:Android malware, banking trojan, crypto theft, Cybersecurity, Google Play Protect, malicious apps, mobile security, Rokarolla, SMS codes, Zimperium

Post navigation

Previous Post: Cyberattack on Novo Nordisk Exposes Medical and AI Data
Next Post: Isira Adithya: Journey from Prodigy to Ethical Hacker

Related Posts

Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures Fake AI Tools Used to Spread Noodlophile Malware, Targeting 62,000+ via Facebook Lures The Hacker News
Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally Vietnamese Hackers Use PXA Stealer, Hit 4,000 IPs and Steal 200,000 Passwords Globally The Hacker News
EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates The Hacker News
Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act Bitfinex Hack Convict Ilya Lichtenstein Released Early Under U.S. First Step Act The Hacker News
Enhance Phishing Detection to Prevent Business Risks Enhance Phishing Detection to Prevent Business Risks The Hacker News
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark