Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Rokarolla Malware Targets Banking Apps with Advanced Tactics

Rokarolla Malware Targets Banking Apps with Advanced Tactics

Posted on June 16, 2026 By CWS

Security researchers have uncovered a new Android malware, named Rokarolla, that poses a significant threat to mobile banking and cryptocurrency applications. This advanced trojan, documented by Zimperium’s zLabs, targets 217 apps and executes 137 remote commands, granting near-total control over infected devices.

How Rokarolla Operates

Rokarolla infiltrates devices through malicious websites that imitate popular applications like TikTok and Chrome. Initially, users are tricked into downloading a dropper disguised as Google Play Protect. This dropper facilitates the installation of the malware’s payload and gains Accessibility access, which is critical for disabling security features such as Google Play Protect.

Upon activation, Rokarolla employs overlay attacks to deceive users. It fetches fake HTML login pages from its server, which are stored locally. When a user opens a legitimate banking or cryptocurrency app, the malware overlays a counterfeit page to capture sensitive information, including login credentials and card details.

Comprehensive Data Theft

Rokarolla employs sophisticated techniques to intercept a wide array of user data. It reads SMS messages and can send them, enabling the interception of one-time passcodes used for secure transactions. By setting itself as the default messaging app, it can block incoming calls, preventing users from receiving alerts from their banks.

The malware includes keylogging and screen logging capabilities, recording everything the user types and sees. It also alters the clipboard contents, replacing copied cryptocurrency wallet addresses with those controlled by the attackers, leading to misdirected transfers.

Cloaked Surveillance and Persistence

For surveillance, Rokarolla forgoes traditional methods like MediaProjection to avoid detection. Instead, it captures and compresses screenshots via Accessibility, sending them to its operators discreetly. This method is less conspicuous than live screen casting used by other malware.

Rokarolla’s resilience is bolstered by multiple fallback command-and-control (C2) domains, allowing it to remain operational even if some servers are disabled. Its extensive command set surpasses that of previous malware like the HOOK trojan, underscoring its threat level.

Defensive Measures and Future Outlook

Currently, there is no specific patch to mitigate Rokarolla, as it exploits user behavior rather than software vulnerabilities. Users are advised to install apps solely from trusted sources like Google Play, keep Play Protect active, and scrutinize any request for Accessibility permissions.

Zimperium’s products can detect Rokarolla, and indicators of compromise are available in their GitHub repository. While the malware’s origins remain unidentified, its design clearly aims to bypass standard security measures, highlighting the need for vigilance and robust mobile security practices.

The Hacker News Tags:Android malware, banking trojan, crypto theft, Cybersecurity, Google Play Protect, malicious apps, mobile security, Rokarolla, SMS codes, Zimperium

Post navigation

Previous Post: Cyberattack on Novo Nordisk Exposes Medical and AI Data
Next Post: Isira Adithya: Journey from Prodigy to Ethical Hacker

Related Posts

OpenAI Enhances Cybersecurity with GPT-5.5-Cyber OpenAI Enhances Cybersecurity with GPT-5.5-Cyber The Hacker News
SEO-Poisoned Sites Exploit ScreenConnect for Malware SEO-Poisoned Sites Exploit ScreenConnect for Malware The Hacker News
Join Webinar to Combat Rapid AI Cyber Threats Join Webinar to Combat Rapid AI Cyber Threats The Hacker News
Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News
The 5 Golden Rules of Safe AI Adoption The 5 Golden Rules of Safe AI Adoption The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark