Rokarolla Now Silences Bank Alerts Too

Rokarolla has moved past simple credential theft. Once it wins Accessibility, SMS, and notification access, it can read what the user sees, grab one-time codes, and shut down the calls and alerts that would normally warn a victim during fraud. Zimperium says the trojan targets 217 banking and crypto apps and can execute 137 commands. It also blocks incoming calls, suppresses device audio, shows fraudulent overlays, and deactivates Google Play Protect, which makes the handset itself part of the fraud path. That breaks the assumption that SMS OTPs and phone-based fraud alerts will interrupt a bad transaction. The same Android device can now feed the attacker codes and stay quiet at the exact moment the bank tries to get the user’s attention.

Part of the PlainSec briefing for 2026-06-16

Every edition of this story: Rokarolla Now Silences Bank Alerts Too

Sources