Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Rokarolla Banking Trojan Targets 200 Applications

The Android malware allows its operators to take control of infected devices and harvest sensitive information.

Android malware

Mobile security firm Zimperium is warning Android users about Rokarolla, a new banking trojan capable of targeting more than 200 cryptocurrency and bank applications.

The malware has been distributed via malicious websites that serve it disguised as popular apps such as Chrome and TikTok. These applications deliver the main payload by impersonating Google Play Protect.

Once it has infected a device, Rokarolla requests a wide range of permissions and can even collect an Android phone’s lockscreen credentials (PIN, pattern, or password), enabling device takeover and the theft of sensitive data even when the phone is locked.

According to Zimperium, the trojan can steal data from 217 banking and cryptocurrency applications, leveraging screen overlays to phish credentials for these apps.

The malware can also harvest WhatsApp contact information by abusing Accessibility Services to capture the active screen’s structure. It can also exfiltrate SMS messages and hijack calls.

Rokarolla also includes keylogger capabilities that enable it to capture everything the victim types. It can also manipulate the clipboard to replace the user’s cryptocurrency addresses with ones controlled by the attacker.

Advertisement. Scroll to continue reading.

In addition, Zimperium noted, “The malware systematically captures screenshots of the victim’s device, compresses them into PNG format, and exfiltrates the image data alongside a precise timestamp.”

The malware uses various methods to evade detection, including disabling Google Play Protect.

“It initially hides its application icon from the device’s app drawer to avoid visual detection,” Zimperium explained. “Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities. This audio suppression effectively masks critical cues, such as security alert notifications or incoming verification calls from banking institutions, significantly reducing the likelihood of the user noticing or interrupting the transaction process.”

Related: Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Related: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.