Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Rokarolla Banking Trojan Targets 200 Applications

The Android malware allows its operators to take control of infected devices and harvest sensitive information.

Android malware

Mobile security firm Zimperium is warning Android users about Rokarolla, a new banking trojan capable of targeting more than 200 cryptocurrency and bank applications.

The malware has been distributed via malicious websites that serve it disguised as popular apps such as Chrome and TikTok. These applications deliver the main payload by impersonating Google Play Protect.

Once it has infected a device, Rokarolla requests a wide range of permissions and can even collect an Android phone’s lockscreen credentials (PIN, pattern, or password), enabling device takeover and the theft of sensitive data even when the phone is locked.

According to Zimperium, the trojan can steal data from 217 banking and cryptocurrency applications, leveraging screen overlays to phish credentials for these apps.

The malware can also harvest WhatsApp contact information by abusing Accessibility Services to capture the active screen’s structure. It can also exfiltrate SMS messages and hijack calls.

Rokarolla also includes keylogger capabilities that enable it to capture everything the victim types. It can also manipulate the clipboard to replace the user’s cryptocurrency addresses with ones controlled by the attacker.

Advertisement. Scroll to continue reading.

In addition, Zimperium noted, “The malware systematically captures screenshots of the victim’s device, compresses them into PNG format, and exfiltrates the image data alongside a precise timestamp.”

The malware uses various methods to evade detection, including disabling Google Play Protect.

“It initially hides its application icon from the device’s app drawer to avoid visual detection,” Zimperium explained. “Complementing this visual evasion, the malware is capable of muting all device audio and vibrations, ensuring it operates in complete silence during fraudulent activities. This audio suppression effectively masks critical cues, such as security alert notifications or incoming verification calls from banking institutions, significantly reducing the likelihood of the user noticing or interrupting the transaction process.”

Related: Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

Related: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages

Related: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

PNC Financial Services Group has appointed Christian Winward as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.