惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
B
Blog
L
LangChain Blog
Y
Y Combinator Blog
美团技术团队
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
量子位
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
Check Point Blog
D
Docker
小众软件
小众软件
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Hackers Use Rokarolla Android Malware to Disable Google P...
Tushar Subhra Dutta · 2026-06-17 · via Cyber Security News

A newly discovered Android banking trojan called Rokarolla is making waves in the cybersecurity world, and it is more dangerous than most threats we have seen lately.

This malware is built to take full control of an infected device while staying completely hidden from the user. Its reach is staggering, with over 217 banking and cryptocurrency applications currently in its crosshairs.

Rokarolla spreads through fake websites that trick users into downloading what appears to be a legitimate app.

The malware disguises itself as well-known applications like TikTok or Google Chrome, making it very easy for unsuspecting users to install it without any suspicion. Once it lands on a device, a dropper component quietly installs the core malicious payload in the background.

Researchers at Zimperium identified this threat through deep technical analysis conducted by their zLabs team, with the findings shared in a report with Cyber Security News (CSN).

The trojan is actually named after its own command and control infrastructure, giving researchers a unique trail to follow. The team found that the malware uses 137 distinct commands to carry out its operations on infected devices.

Dropper installs the second stage while impersonating a legitimate app (Source - Zimperium)
Dropper installs the second stage while impersonating a legitimate app (Source – Zimperium)

The scale of what Rokarolla can do is alarming even for seasoned security professionals. It captures lock screen PINs and passwords using fake overlays, silently reads all SMS messages, and logs every keystroke on the device.

All of this stolen data gets sent back to attacker-controlled servers without the victim ever knowing it happened. One of the most concerning aspects of this trojan is how aggressively it covers its tracks.

It hides its app icon from the device drawer, mutes all sounds and vibrations to mask bank alert notifications, and even forces the screen to stay on so its automated tasks are never interrupted. For anyone with sensitive financial apps on their phone, this threat is a serious wake-up call.

Hackers Use Rokarolla Android Malware

Rokarolla goes out of its way to kill Android’s built-in security layer before settling in. It uses specific commands including disable_google_play and protectorgoogle_disable to strip away Google Play Protect, effectively leaving the device blind to further threats.

With that protection gone, the malware gains a wide-open path to carry out its full range of malicious activities.

The trojan abuses Android’s Accessibility Services, a feature normally used to help people with disabilities, to interact with the screen on behalf of the attacker.

It maps out every UI element, monitors active apps, and injects fake login pages on top of real banking apps to steal credentials. When a user thinks they are logging into their bank, they are actually handing their details directly to the attacker.

Banker malware impersonating a legitimate app and requesting Accessibility Service (Source - Zimperium)
Banker malware impersonating a legitimate app and requesting Accessibility Service (Source – Zimperium)

The malware also employs a snapshot-based screen monitoring method rather than the more common live screen casting approach. It captures screenshots at regular intervals, compresses them, and transmits them with timestamps to remote servers.

This gives attackers a near-real-time view of everything happening on the victim’s device.

Silent Data Theft and Command Control Infrastructure

Rokarolla is equally dangerous when it comes to stealing data beyond login credentials. It intercepts SMS messages including bank OTPs, blocks incoming calls from financial institutions, and silently overwrites clipboard content to redirect cryptocurrency wallet addresses.

The attacker can redirect a financial transaction without the user ever noticing the switch. The malware communicates with its command and control servers over HTTPS to blend in with normal traffic.

It sends a full device profile on first contact, including hardware details, battery status, and storage information, to generate a unique bot ID. The malware also supports multiple fallback domains and can dynamically switch between them if one gets blocked.

To stay safe, users should avoid installing apps from outside the official Google Play Store and be very cautious about granting Accessibility Service permissions to any application.

Keeping Android security patches up to date and using a mobile threat defense solution can significantly reduce the risk of infection from threats like Rokarolla.

Indicators of Compromise (IoCs):-

The following IoCs were identified in the Zimperium zLabs research report.

TypeIndicatorDescription
URLhxxps[://]infocontablidades[.]it[.]com/Primary malware distribution site masquerading as TikTok or Google Chrome
Domainberalisvc[.]infoC2 fallback domain used for malware communication
Domainblestorians[.]cfdC2 fallback domain used for malware communication
Domainabiorime[.]cfdC2 fallback domain used for malware communication
Domainmorevoms[.]cfdC2 fallback domain used for malware communication

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.