The Rokarolla Android banking trojan targets 217 financial and cryptocurrency applications via malicious websites impersonating apps like TikTok and Chrome. It gains control by tricking users into enabling accessibility services, allowing it to execute 137 commands for device takeover. The primary defense is user education to avoid sideloading apps from unofficial sources, as no specific affected or patched software versions are detailed in the article.
A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app. Banker malware impersonating a legitimate app and requesting accessibility service (Source: Zimperium) Zimperium said … More → The post Rokarolla Android trojan targets banking and crypto users, enables device takeover appeared first on Help Net Security .