Rokarolla Android Malware Steals Banking Credentials and Enables Device Surveillance (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Targets 217 banking and crypto apps with 137 commands
- Abuses Accessibility Services for overlay attacks and keylogging
- Intercepts SMS and calls to block fraud alerts
- Exfiltrates screenshots and swaps clipboard for crypto theft
"Security researchers at Zimperium's zLabs have identified a new Android banking trojan named Rokarolla that targets 217 banking and cryptocurrency apps. The malware spreads via fake TikTok and Chrome sites, using a Google Play Protect-themed dropper. It abuses Accessibility Services to steal login credentials, intercept SMS one-time codes, block calls, and hide notifications. Rokarolla can also replace clipboard content to redirect cryptocurrency payments. The trojan exfiltrates screenshots and attempts to disable Google Play Protect."
no comments yet.