securityaffairs.com 6/17/2026, 11:50:42 AM · external

Rokarolla Android Trojan hits banks via fake TikTok, Chrome apps

Rokarolla Android Trojan hits banks via fake TikTok, Chrome apps
Developing story breach 4 articles tracked
Rokarolla Android banking trojan targets banks via fake TikTok and Chrome apps
CyberSIXT Evidence Panel
Primary Source zimperium.com

THE article discusses the Rokarolla Android Trojan, which targets 217 banking and crypto applications, stealing user credentials and interfering with device functionality. This malware spreads through malicious sites disguised as popular apps like TikTok and Google Chrome, using a dropper that masquerades as Google Play Protect to gain access. Once installed, it can simulate user taps, display fraudulent overlays to capture sensitive information, and intercept SMS messages.

Rokarolla can block incoming calls, mute device sounds, and silently rewrite clipboard data, making it highly evasive and persistent. Researchers from Zimperium advise against granting accessibility access to unknown apps and stress the importance of downloading apps only from trusted sources.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline