0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Rokarolla Android Malware Steals Banking Credentials and Enables Device Surveillance (infosecurity-magazine.com)

· 41d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Targets 217 banking and crypto apps with 137 commands
  • Abuses Accessibility Services for overlay attacks and keylogging
  • Intercepts SMS and calls to block fraud alerts
  • Exfiltrates screenshots and swaps clipboard for crypto theft

"Security researchers at Zimperium's zLabs have identified a new Android banking trojan named Rokarolla that targets 217 banking and cryptocurrency apps. The malware spreads via fake TikTok and Chrome sites, using a Google Play Protect-themed dropper. It abuses Accessibility Services to steal login credentials, intercept SMS one-time codes, block calls, and hide notifications. Rokarolla can also replace clipboard content to redirect cryptocurrency payments. The trojan exfiltrates screenshots and attempts to disable Google Play Protect."

Discussion Matrix

0 segments

no comments yet.