惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Jina AI
Jina AI
J
Java Code Geeks
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
I
InfoQ
L
LangChain Blog
The Cloudflare Blog
IT之家
IT之家
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Last Week in AI
Last Week in AI
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
博客园 - 聂微东
美团技术团队
博客园_首页

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Rokarolla Android trojan targets banking and crypto users...
Sinisa Markovic · 2026-06-17 · via Help Net Security

A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium.

Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app.

Rokarolla Android banking trojan

Banker malware impersonating a legitimate app and requesting accessibility service (Source: Zimperium)

Zimperium said Rokarolla is designed to steal financial information while giving attackers broad control over compromised devices.

“Its malicious capabilities include harvesting lock screen credentials, exfiltrating sensitive contact lists and SMS data, and utilizing keyloggers to continuously record user input,” the researchers said.

“Furthermore, the trojan actively conceals its operations and disrupts user intervention by blocking incoming calls, deploying fraudulent screen overlays, suppressing device audio, and deactivating Google Play Protect.”

The attack begins with a dropper that poses as Google Play Protect, Google’s Android security service. Once installed, it delivers a second-stage payload containing the Rokarolla malware.

When launched on the device, Rokarolla requests access to Android Accessibility Services, along with permissions for notifications and SMS messages.

Rokarolla uses phishing overlays to steal financial data

The malware then checks infected devices for any of the 217 banking and cryptocurrency applications on its target list. When it finds one, Rokarolla downloads a phishing page that is displayed as an overlay when the victim opens the legitimate app, allowing attackers to collect credentials, credit card information, and other financial data.

Rokarolla Android banking trojan

Fake Overlay process of Imagin bank (Source: Zimperium)

Rokarolla exchanges data with its C2 infrastructure, sending details about the device, Android version, locale, battery status, and available storage. According to Zimperium, this information is used to generate a unique botID for each infected device.

The malware can receive commands from its operators and switch to alternative C2 domains through remote configuration. The researchers identified 137 commands used to control infected devices.

SMS interception and device surveillance capabilities

“The malware has the capability of exfiltrating all SMS messages from the infected device and can also send SMS on behalf of the victim, which can be used to intercept sensitive information such as bank OTPs,” the researchers said.

Rokarolla can also extract text displayed on the screen and gather information from messaging applications. The researchers found that it can modify clipboard contents without user interaction, a capability that can be used to replace cryptocurrency wallet addresses and other copied data.

Instead of relying on continuous screen streaming, Rokarolla periodically captures screenshots of infected devices and sends them to its operators. This provides visibility into user activity and information displayed on the screen.

Another capability allows Rokarolla to block and intercept phone calls, giving attackers a way to disrupt fraud alerts and other security-related communications from banks.

“Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities,” they added.

Zimperium published a list of indicators of compromise (IoCs) on a GitHub page. The company also included a complete list of MITRE ATT&CK tactics and techniques associated with the Rokarolla attack chain.