Malware · 88 days ago
Rokarolla Now Silences Bank Alerts Too Rokarolla has moved past simple credential theft. Once it wins Accessibility, SMS, and notification access, it can read what the user sees, grab one-time codes, and shut down the calls and alerts that would normally warn a victim during fraud.
Zimperium says the trojan targets 217 banking and crypto apps and can execute 137 commands. It also blocks incoming calls, suppresses device audio, shows fraudulent overlays, and deactivates Google Play Protect, which makes the handset itself part of the fraud path.
That breaks the assumption that SMS OTPs and phone-based fraud alerts will interrupt a bad transaction. The same Android device can now feed the attacker codes and stay quiet at the exact moment the bank tries to get the user’s attention.
Timeline Sources 6 sources covering this story
SecurityWeek Jun 18
Rokarolla Banking Trojan Targets 200 Applications
The Android malware allows its operators to take control of infected devices and harvest sensitive information.
Help Net Security Jun 17
Rokarolla Android trojan targets banking and crypto users, enables device takeover - Help Net Security
Rokarolla, a newly discovered Android banking trojan, uses phishing overlays and SMS theft to target financial apps.
The Hacker News Jun 16
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Rokarolla targets 217 banking and crypto apps with 137 commands, enabling PIN, SMS code, and crypto payment theft.
Dark Reading Jun 16
Rokarolla Android Trojan Levels Up to Full Device Control, Persistence
The malware, spread via fake TikTok and Chrome downloads, has evolved by combining banking fraud with surveillance and remote control.
BleepingComputer Jun 16
New Rokarolla Android malware targets 217 banking, crypto apps
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands.
Infosecurity Magazine Jun 16
Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Rokarolla Android trojan steals banking logins and spies on victims while blocking fraud alerts
Part of the PlainSec briefing for 2026-06-16
Editions Related stories
Malware · 88 days ago
Rokarolla Now Silences Bank Alerts Too Rokarolla has moved past simple credential theft. Once it wins Accessibility, SMS, and notification access, it can read what the user sees, grab one-time codes, and shut down the calls and alerts that would normally warn a victim during fraud.
Zimperium says the trojan targets 217 banking and crypto apps and can execute 137 commands. It also blocks incoming calls, suppresses device audio, shows fraudulent overlays, and deactivates Google Play Protect, which makes the handset itself part of the fraud path.
That breaks the assumption that SMS OTPs and phone-based fraud alerts will interrupt a bad transaction. The same Android device can now feed the attacker codes and stay quiet at the exact moment the bank tries to get the user’s attention.
Timeline Sources 6 sources covering this story
SecurityWeek Jun 18
Rokarolla Banking Trojan Targets 200 Applications
The Android malware allows its operators to take control of infected devices and harvest sensitive information.
Help Net Security Jun 17
Rokarolla Android trojan targets banking and crypto users, enables device takeover - Help Net Security
Rokarolla, a newly discovered Android banking trojan, uses phishing overlays and SMS theft to target financial apps.
The Hacker News Jun 16
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Rokarolla targets 217 banking and crypto apps with 137 commands, enabling PIN, SMS code, and crypto payment theft.
Dark Reading Jun 16
Rokarolla Android Trojan Levels Up to Full Device Control, Persistence
The malware, spread via fake TikTok and Chrome downloads, has evolved by combining banking fraud with surveillance and remote control.
BleepingComputer Jun 16
New Rokarolla Android malware targets 217 banking, crypto apps
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands.
Infosecurity Magazine Jun 16
Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Rokarolla Android trojan steals banking logins and spies on victims while blocking fraud alerts
Part of the PlainSec briefing for 2026-06-16
Editions Related stories