securityonline.info 6/25/2026, 7:10:51 AM · external

Rokarolla Android Trojan Takes Devices, Steals Crypto & Bank Data

Rokarolla Android Trojan Takes Devices, Steals Crypto & Bank Data
Developing story breach 6 articles tracked
Rokarolla Android banking trojan steals cryptocurrency and bank credentials
CyberSIXT Evidence Panel
Primary Source zimperium.com

THE Rokarolla Android banking trojan is a malware that executes complete device takeovers, targeting 217 cryptocurrency and banking applications. It is spread through malicious websites impersonating legitimate apps, tricking users into installing a dropper application that delivers the trojan. After gaining Accessibility Services access, it conceals its icon, connects to a remote server, and downloads fake HTML phishing pages for banking apps to capture user credentials.

The malware employs tactics like disabling Google Play Protect, sending SMS messages impersonating the victim, and bypassing two-factor authentication. Users are advised to avoid unofficial app downloads and scrutinize app permissions to protect against this threat.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline