惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Recent Announcements
Recent Announcements
Vercel News
Vercel News
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
G
Google Developers Blog
罗磊的独立博客
爱范儿
爱范儿
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
月光博客
月光博客
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Rokarolla Android trojan targets banking and crypto users...
Sinisa Markovic · 2026-06-17 · via Help Net Security

A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium.

Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app.

Rokarolla Android banking trojan

Banker malware impersonating a legitimate app and requesting accessibility service (Source: Zimperium)

Zimperium said Rokarolla is designed to steal financial information while giving attackers broad control over compromised devices.

“Its malicious capabilities include harvesting lock screen credentials, exfiltrating sensitive contact lists and SMS data, and utilizing keyloggers to continuously record user input,” the researchers said.

“Furthermore, the trojan actively conceals its operations and disrupts user intervention by blocking incoming calls, deploying fraudulent screen overlays, suppressing device audio, and deactivating Google Play Protect.”

The attack begins with a dropper that poses as Google Play Protect, Google’s Android security service. Once installed, it delivers a second-stage payload containing the Rokarolla malware.

When launched on the device, Rokarolla requests access to Android Accessibility Services, along with permissions for notifications and SMS messages.

Rokarolla uses phishing overlays to steal financial data

The malware then checks infected devices for any of the 217 banking and cryptocurrency applications on its target list. When it finds one, Rokarolla downloads a phishing page that is displayed as an overlay when the victim opens the legitimate app, allowing attackers to collect credentials, credit card information, and other financial data.

Rokarolla Android banking trojan

Fake Overlay process of Imagin bank (Source: Zimperium)

Rokarolla exchanges data with its C2 infrastructure, sending details about the device, Android version, locale, battery status, and available storage. According to Zimperium, this information is used to generate a unique botID for each infected device.

The malware can receive commands from its operators and switch to alternative C2 domains through remote configuration. The researchers identified 137 commands used to control infected devices.

SMS interception and device surveillance capabilities

“The malware has the capability of exfiltrating all SMS messages from the infected device and can also send SMS on behalf of the victim, which can be used to intercept sensitive information such as bank OTPs,” the researchers said.

Rokarolla can also extract text displayed on the screen and gather information from messaging applications. The researchers found that it can modify clipboard contents without user interaction, a capability that can be used to replace cryptocurrency wallet addresses and other copied data.

Instead of relying on continuous screen streaming, Rokarolla periodically captures screenshots of infected devices and sends them to its operators. This provides visibility into user activity and information displayed on the screen.

Another capability allows Rokarolla to block and intercept phone calls, giving attackers a way to disrupt fraud alerts and other security-related communications from banks.

“Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities,” they added.

Zimperium published a list of indicators of compromise (IoCs) on a GitHub page. The company also included a complete list of MITRE ATT&CK tactics and techniques associated with the Rokarolla attack chain.