www.malwarebytes.com 6/17/2026, 4:10:24 PM · external

Rokarolla malware steals bank, crypto logins via fake overlays

Rokarolla malware steals bank, crypto logins via fake overlays
Developing story breach 4 articles tracked
Rokarolla Android banking trojan targets banks via fake TikTok and Chrome apps
CyberSIXT Evidence Panel
Primary Source zimperium.com

THE article discusses a new Android malware named Rokarolla, which can completely take over devices and steal sensitive banking and cryptocurrency login details from over 200 apps. It uses deceptive overlay screens to capture user information, including PINs and passwords, and exploits Android's Accessibility features to monitor activity, intercept SMS, and manipulate phone functions.

Rokarolla is typically distributed via rogue websites posing as legitimate app downloads, tricking users into granting extensive permissions. To protect against such threats, users are advised not to trust apps claiming to be system components, avoid sideloading apps, and be cautious with permissions.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline