Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Europe’s Crypto Firms Face Squeeze as MiCA Transition Period End Looms

June 20, 2026

Aerodrome Finance surges 14% – AERO eyes THESE key levels next

June 20, 2026

GARVEE Teams Up with TikTok Shop for Super Brand Day, Bringing Exclusive Limited-Time Deals Across Summer Cooling, Outdoor Living and Best-Selling Home Essentials

June 20, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Rokarolla Trojan Combines Banking Fraud With Device Surveillance
Security and Privacy

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A newly discovered Android banking trojan has been observed going beyond draining accounts, seizing near-total control of a phone and cutting victims off from their banks so fraud can run undetected.

Named Rokarolla after its command-and-control (C2) servers, the malware was detailed by zLabs, the research arm of mobile security firm Zimperium, which found it targeting 217 banking and cryptocurrency apps through a toolkit of 137 commands.

It spreads through malicious sites that masquerade as TikTok or Google Chrome, using a dropper that poses as Google Play Protect to slip a second-stage payload past Android’s defenses and onto the device.

“The Rokarolla trojan marks a shift from data theft to victim isolation,” explained Jason Soroko, senior fellow at certificate-management firm Sectigo, who described Rokarolla turning the phone into a weapon against its owner.

Read more: Android Malware Targets Banking Users Through Discord Channels

To keep that grip, Rokarolla makes itself the device’s default handler for calls and texts. It can block incoming calls and read or send SMS messages, letting it swallow the one-time codes and fraud alerts a bank would normally use to flag a suspect transfer.

It also mutes the phone’s audio and vibration to hide alert tones, hides its own icon from the app drawer and forces the screen to stay awake so its hidden activity is never interrupted.

Fake Screens and Stolen Logins

The theft leans on Accessibility Services, the Android feature for assistive apps, which Rokarolla abuses to read the screen and drive the interface. From there it harvests:

  • Banking and crypto logins, captured by fake overlay screens

  • Lock screen PINs, patterns and passwords

  • Keystrokes and on-screen text

  • SMS messages, including bank one-time codes

  • WhatsApp contacts, scraped from the display

See also  Binance.US Halts US Dollar Deposits Over Banking Challenges, Says It Will Temporarily Be a Crypto-Only Exchange

When a victim opens a targeted app, the malware drops a convincing fake login page, fetched from its server, over the real one.

It can also rewrite the clipboard on the fly, swapping in an attacker’s cryptocurrency wallet address when the victim copies their own.

For surveillance, rather than streaming the screen live, Rokarolla quietly takes timestamped screenshots and exfiltrates them one by one. It also tries to disable Google Play Protect to keep itself hidden.

The campaign coincides with a substantial increase in mobile threats. Randolph Barr, CISO at API security firm Cequence Security, noted, “Android continues to face banking trojans and data-leaking SDKs,” citing tens of millions of mobile malware incidents blocked in 2024 alone.

Source link

Banking Combines Device Fraud Rokarolla surveillance Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Florida Man ‘Bitcoin Rodney’ Pleads Guilty Over $1.8 Billion HyperFund Crypto Fraud

June 19, 2026

Fake GitHub Stars and AI Videos Mask a Crypto Clipper

June 18, 2026

HyperFund Promoter Pleads Guilty In $1.8B Crypto Fraud Cas

June 18, 2026

Zcash Climbs 80% Since June 5 as Traders Shrug off Orchard Bug Fears – Bitcoin News

June 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Where’re We Going Here? (Why Can’t the Crypto Market Make Its Mind Up?)

April 26, 2024

Solana RWA holders jump 440% YoY – Can it bridge gap to Ethereum’s XAUT?

April 6, 2026

Coin Center responds to US lawmakers’ request for crypto tax guidance

August 24, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Europe’s Crypto Firms Face Squeeze as MiCA Transition Period End Looms

June 20, 2026

Aerodrome Finance surges 14% – AERO eyes THESE key levels next

June 20, 2026

GARVEE Teams Up with TikTok Shop for Super Brand Day, Bringing Exclusive Limited-Time Deals Across Summer Cooling, Outdoor Living and Best-Selling Home Essentials

June 20, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,600.001.78%
  • ethereumEthereum(ETH)$1,725.612.01%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$586.422.47%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.152.08%
  • solanaSolana(SOL)$71.594.83%
  • tronTRON(TRX)$0.3234700.68%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.032.13%
  • HyperliquidHyperliquid(HYPE)$70.895.74%