{"id":15787,"date":"2026-06-16T16:50:44","date_gmt":"2026-06-16T16:50:44","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15787"},"modified":"2026-06-16T16:50:44","modified_gmt":"2026-06-16T16:50:44","slug":"new-rokarolla-android-malware-steals-pins-sms-codes-and-crypto-pockets-funds","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15787","title":{"rendered":"New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Pockets Funds"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 16, 2026<\/span><\/span><span class=\"p-tags\">Cellular Safety \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjF_U2JZgjmQGUfV3q90DEMUgqHK2kqloGQR5lBYn_8UUC2DUIFpJPpCnETlOUh1IldJXcWdr9YZ5hA3yUtZETvviRousyQt7En5mNSjwoJiD_gJ9_kjS7L8ujw_y6CN3NeygZWa-sXCEG1zo5PBmuB5CkSP-EYxBWsUEtUq4iYJ3AYXHVM_TscyngMwPU\/s1600\/android-banking-trojan.jpg\" style=\"clear: left; display: block; float: left; padding: 1em 0px; text-align: center;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjF_U2JZgjmQGUfV3q90DEMUgqHK2kqloGQR5lBYn_8UUC2DUIFpJPpCnETlOUh1IldJXcWdr9YZ5hA3yUtZETvviRousyQt7En5mNSjwoJiD_gJ9_kjS7L8ujw_y6CN3NeygZWa-sXCEG1zo5PBmuB5CkSP-EYxBWsUEtUq4iYJ3AYXHVM_TscyngMwPU\/s1600\/android-banking-trojan.jpg\"\/><\/a><\/div>\n<p>Safety researchers at\u00a0Zimperium&#8217;s zLabs\u00a0have documented a brand new Android banking trojan, <b>Rokarolla<\/b>, that targets 217 banking and cryptocurrency apps and packs 137 distant instructions.<\/p>\n<p>Collectively, they offer an operator near-total management of an contaminated cellphone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto funds, and switches off Google Play Defend.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/zimperium.com\/blog\/rokarolla-android-banker-with-complete-device-takeover-capabilities\" target=\"_blank\">Rokarolla<\/a>, named after its command-and-control servers, spreads by means of malicious web sites posing as well-known apps reminiscent of TikTok and Chrome.<\/p>\n<p>The very first thing a sufferer installs is a dropper that pretends to be Google Play Defend. It makes use of that disguise to get the payload put in and seize Accessibility entry. As soon as the malware is operating, one in every of its instructions turns Play Defend off.<\/p>\n<p><\/p>\n<p>The theft runs by means of overlays. Rokarolla pulls a goal record from its server, and for every app flagged lively, it downloads a pretend HTML login web page and shops it in a neighborhood database. When the sufferer opens the actual banking or pockets app, the malware drops the pretend web page on prime and captures every part typed into it, card particulars included.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"more\"\/><\/p>\n<p>The report reveals one such pretend web page mimicking the banking app &#8216;imagin.&#8217; A separate overlay mimics the Android lock display screen to seize the PIN, sample, or password, which lets the operator management the cellphone even whereas it&#8217;s locked.<\/p>\n<p>It reads each SMS on the system and may ship messages itself, which is sufficient to seize the SMS one-time codes banks use to approve logins and transactions. By making itself the cellphone&#8217;s default app for texts and calls, it will possibly additionally block incoming calls, so a warning name from the financial institution by no means will get by means of.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEii38LbNz47rDhQGeGb9HNSZeyWHqe1BynQOAGFAKTs5nOYOBksLGtnmjf2nooFasfriLdunWaqmqOZFHsd_RpAVoZnY3SIg-jmjChinICWEi323uEsrbEko9swMzI_DDUBeOPCGm_m-8TbOT9Ixt3m1hPTwHdn2VarlvJedLRoXnghp571-uFhdyFac0M\/s1600\/android-hack.jpg\" style=\"clear: left; display: block; float: left; padding: 1em 0px; text-align: center;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"622\" data-original-width=\"1000\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEii38LbNz47rDhQGeGb9HNSZeyWHqe1BynQOAGFAKTs5nOYOBksLGtnmjf2nooFasfriLdunWaqmqOZFHsd_RpAVoZnY3SIg-jmjChinICWEi323uEsrbEko9swMzI_DDUBeOPCGm_m-8TbOT9Ixt3m1hPTwHdn2VarlvJedLRoXnghp571-uFhdyFac0M\/s1600\/android-hack.jpg\"\/><\/a><\/div>\n<p>A keylogger and display screen logger report what the person varieties and sees, and the trojan scrapes contacts and reads notifications. The clipboard will get rewritten silently, swapping in attacker pockets addresses so a copied crypto fee lands within the mistaken account.<\/p>\n<p>For surveillance, Rokarolla skips the standard MediaProjection display screen casting, which throws a visual recording immediate, and as an alternative takes screenshots by means of Accessibility, compresses them to PNG, and ships them out one body at a time. That snapshot strategy is less complicated and quieter than the stay hidden VNC seen in households like\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/10\/new-android-banking-trojan-klopatra.html\">Klopatra<\/a>.<\/p>\n<p><\/p>\n<p>The malware carries a number of fallback C2 domains and might be handed new ones on the fly, so pulling a single server does little. It is 137 instructions outnumber the 107 Zimperium counted within the\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/08\/hook-android-trojan-adds-ransomware.html\">HOOK trojan<\/a>, and the playbook is similar one operating by means of a\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/zimperium.com\/blog\/android-bankers-4-campaigns-in-a-row\">wave of 2026 Android bankers<\/a>: fake-app droppers, Accessibility abuse, and HTML overlays.<\/p>\n<p>There is no such thing as a patch to use right here. That is malware, not a product flaw, so the defenses are the usual ones for Android bankers. Set up apps solely from Google Play, go away Play Defend on, and deal with any sudden Accessibility request as a crimson flag, since that one permission drives the entire assault chain.<\/p>\n<p>Zimperium says its personal merchandise detect the household, and the symptoms of compromise are in its\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/Zimperium\/IOC\/tree\/master\/2026-06-Rokarolla\">GitHub repository<\/a>.<\/p>\n<p>Zimperium didn&#8217;t tie Rokarolla to a named group. What the construct reveals is intent: a banker put collectively to beat the precise protections customers are instructed to depend on, from Play Defend all the way down to the lock display screen.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jun 16, 2026Cellular Safety \/ Malware Safety researchers at\u00a0Zimperium&#8217;s zLabs\u00a0have documented a brand new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 distant instructions. Collectively, they offer an operator near-total management of an contaminated cellphone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15789,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[797,1135,662,6795,216,9450,9449,1177,3578,663],"class_list":["post-15787","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-android","tag-codes","tag-crypto","tag-funds","tag-malware","tag-pins","tag-rokarolla","tag-sms","tag-steals","tag-wallet"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15787","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15787"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15787\/revisions"}],"predecessor-version":[{"id":15788,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15787\/revisions\/15788"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15789"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15787"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15787"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15787"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-16 18:59:39 UTC -->