tech
A new Android trojan called Rokarolla targets 217 banking apps and can steal your PIN, SMS codes, and crypto wallet funds
Zimperium found Rokarolla, an Android trojan targeting 217 banking apps with 137 commands. It steals PINs, intercepts SMS, and hijacks crypto payments.

TL;DR
- Rokarolla is a new Android banking trojan targeting 217 banking and cryptocurrency applications.
- It possesses 137 remote commands, granting operators significant control over infected devices.
- The malware can steal lock-screen PINs, read/send SMS messages, rewrite the clipboard to redirect cryptocurrency payments, and disable Google Play Protect.
- Rokarolla spreads via malicious websites impersonating popular apps, using a fake Google Play Protect dropper to gain Accessibility access.
- It employs HTML overlays to mimic banking app login pages, capturing credentials, and also harvests device PINs/passwords via a fake lock screen overlay.
- The trojan intercepts SMS messages, including one-time codes, and can block incoming calls to prevent fraud alerts.
- Keylogging, screen logging, contact scraping, and notification reading are also features of Rokarolla.
- It uses Accessibility for screenshot capture, bypassing MediaProjection prompts.
- Rokarolla maintains multiple fallback command-and-control domains for resilience.
- Standard defenses include installing apps only from Google Play, keeping Play Protect enabled, and being cautious of Accessibility permission requests.