New Rokarolla Android malware targets 217 banking, crypto apps
Rokarolla is a new Android banking trojan targeting 217 banking and cryptocurrency applications. It uses 137 commands to gain near-complete administrative control of infected devices, stealing lock screen credentials, contact lists, SMS messages, and keystrokes. Distributed via malicious websites masquerading as Google Chrome or TikTok apps, it requests extensive permissions including Accessibility services to bypass security. Rokarolla displays phishing overlays to steal financial data and uses evasion tactics such as disabling Google Play Protect and hiding its icon. It is not found on Google Play, and users are advised to avoid installing APKs from untrusted sources and be cautious with Accessibility permissions.
AI Analysis
Technical Summary
Rokarolla is an Android banking trojan that targets 217 specific banking and cryptocurrency apps by deploying phishing overlays to steal login credentials and financial data. It is distributed through malicious websites pretending to offer legitimate apps like Google Chrome or TikTok. Upon installation, it requests Accessibility, notification, SMS, and call permissions to gain extensive control over the device. The malware collects device profile data to uniquely identify victims and uses 137 commands to steal SMS, contacts, keystrokes, screenshots, and manipulate clipboard contents. It employs evasion techniques such as disabling Google Play Protect, hiding its app icon, silencing audio/vibration, and keeping the screen awake. Rokarolla's primary goal is financial theft through advanced fraud enabled by its administrative control. It has not been detected on the official Google Play store.
Potential Impact
The malware enables attackers to steal sensitive financial information including login credentials, credit card data, SMS messages, and contact lists from infected Android devices. It can capture lock screen PINs/patterns and operate the device while locked, facilitating unauthorized transactions and fraud. Rokarolla's extensive command set allows persistent surveillance and manipulation of user data and device functions, posing a significant risk of financial loss and privacy breaches for victims.
Mitigation Recommendations
No official patch or fix is applicable as this is malware rather than a software vulnerability. Users should avoid downloading APK files from untrusted sources and only install apps from the official Google Play store. Exercise caution when granting Accessibility service permissions, as these can be exploited by malware to gain elevated control. Security teams should educate users about the risks of sideloading apps and monitor for suspicious device behavior indicative of malware infection.
New Rokarolla Android malware targets 217 banking, crypto apps
Description
Rokarolla is a new Android banking trojan targeting 217 banking and cryptocurrency applications. It uses 137 commands to gain near-complete administrative control of infected devices, stealing lock screen credentials, contact lists, SMS messages, and keystrokes. Distributed via malicious websites masquerading as Google Chrome or TikTok apps, it requests extensive permissions including Accessibility services to bypass security. Rokarolla displays phishing overlays to steal financial data and uses evasion tactics such as disabling Google Play Protect and hiding its icon. It is not found on Google Play, and users are advised to avoid installing APKs from untrusted sources and be cautious with Accessibility permissions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Rokarolla is an Android banking trojan that targets 217 specific banking and cryptocurrency apps by deploying phishing overlays to steal login credentials and financial data. It is distributed through malicious websites pretending to offer legitimate apps like Google Chrome or TikTok. Upon installation, it requests Accessibility, notification, SMS, and call permissions to gain extensive control over the device. The malware collects device profile data to uniquely identify victims and uses 137 commands to steal SMS, contacts, keystrokes, screenshots, and manipulate clipboard contents. It employs evasion techniques such as disabling Google Play Protect, hiding its app icon, silencing audio/vibration, and keeping the screen awake. Rokarolla's primary goal is financial theft through advanced fraud enabled by its administrative control. It has not been detected on the official Google Play store.
Potential Impact
The malware enables attackers to steal sensitive financial information including login credentials, credit card data, SMS messages, and contact lists from infected Android devices. It can capture lock screen PINs/patterns and operate the device while locked, facilitating unauthorized transactions and fraud. Rokarolla's extensive command set allows persistent surveillance and manipulation of user data and device functions, posing a significant risk of financial loss and privacy breaches for victims.
Mitigation Recommendations
No official patch or fix is applicable as this is malware rather than a software vulnerability. Users should avoid downloading APK files from untrusted sources and only install apps from the official Google Play store. Exercise caution when granting Accessibility service permissions, as these can be exploited by malware to gain elevated control. Security teams should educate users about the risks of sideloading apps and monitor for suspicious device behavior indicative of malware infection.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/","fetched":true,"fetchedAt":"2026-06-16T20:15:14.391Z","wordCount":817}
Threat ID: 6a31aed20b89be68881f1e3c
Added to database: 6/16/2026, 8:15:14 PM
Last enriched: 6/16/2026, 8:15:22 PM
Last updated: 6/17/2026, 4:21:12 AM
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.