Rokarolla is an Android banking trojan focused on financial fraud and broad device takeover. It targets at least 217 banking and cryptocurrency applications and is operated through an extensive command set reported at 137 commands, indicating a mature mobile malware platform with substantial remote-control functionality.
Rokarolla is distributed through malicious websites that impersonate trusted Android applications and download portals, including lures themed as popular consumer apps and a dropper masquerading as Google Play Protect. The dropper installs a second-stage payload and seeks elevated permissions, especially Android Accessibility Services, along with access to SMS, notifications, and call-handling functions.
Once installed, Rokarolla abuses Accessibility Services to inspect on-screen content, parse interface elements, automate user-interface actions, and deploy phishing overlays over legitimate banking and cryptocurrency apps. It retrieves targeted application lists and overlay content from command-and-control infrastructure, then presents fake login or lock-screen prompts to steal usernames, passwords, payment card data, and device unlock credentials such as PINs, patterns, and passwords. It also supports keylogging and extraction of on-screen text.
The malware is designed to defeat common fraud controls by intercepting and exfiltrating SMS messages, including one-time passcodes, sending SMS messages from the victim device, setting itself as the default handler for calls and texts, and blocking or intercepting incoming calls that could warn victims about fraudulent activity. Additional surveillance and theft functions include screenshot capture with exfiltration, contact and messaging-app data harvesting, and clipboard manipulation to replace copied cryptocurrency wallet addresses with attacker-controlled ones.
Rokarolla includes multiple defense-evasion and stealth features. Reported behaviors include attempting to disable Google Play Protect, hiding its launcher icon, muting audio and vibration, and keeping the screen awake to preserve overlays and automated actions. It also uses resilient command-and-control mechanisms such as fallback infrastructure and dynamic configuration updates. No high-confidence attribution to a named threat actor is established in the available reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The theft leans on Accessibility Services, the Android feature for assistive apps, which Rokarolla abuses to read the screen and drive the interface.
From there it harvests: Banking and crypto logins, captured by fake overlay screens Lock screen PINs, patterns and passwords Keystrokes and on-screen text
This lets it silently log keystrokes, extract on-screen text, and harvest contact information from apps like WhatsApp.
When a victim opens a targeted app, the malware drops a convincing fake login page, fetched from its server, over the real one.
When a targeted application is launched, Rokarolla displays a fraudulent HTML-based overlay that mimics the legitimate application's login interface. Victims may unknowingly enter usernames, passwords, payment card information, and other sensitive data into the fraudulent interface, which is subsequently transmitted to attacker-controlled infrastructure.
Beyond stealing login credentials, the trojan collects device unlock PINs and passwords... read on-screen content... harvest contact information from apps like WhatsApp.
From there it harvests: Banking and crypto logins, captured by fake overlay screens Lock screen PINs, patterns and passwords Keystrokes and on-screen text
This lets it silently log keystrokes, extract on-screen text, and harvest contact information from apps like WhatsApp.
When a victim opens a targeted app, the malware drops a convincing fake login page, fetched from its server, over the real one.
When a targeted application is launched, Rokarolla displays a fraudulent HTML-based overlay that mimics the legitimate application's login interface. Victims may unknowingly enter usernames, passwords, payment card information, and other sensitive data into the fraudulent interface, which is subsequently transmitted to attacker-controlled infrastructure.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan that masquerades as legitimate apps, uses phishing overlays to steal banking and cryptocurrency credentials, intercepts SMS one-time passcodes, abuses Accessibility Services for automation and screen/content capture, monitors the clipboard to swap crypto wallet addresses, captures screenshots, and blocks fraud alert calls while maintaining resilient fallback C2 infrastructure.
Android banking trojan that targets banking and cryptocurrency applications using phishing overlays, Android Accessibility Services abuse, SMS interception, keylogging, screen monitoring, call blocking, clipboard manipulation, and extensive remote command capabilities to facilitate financial fraud and account compromise.
Android banking trojan distributed via malicious websites masquerading as popular apps such as Chrome and TikTok. It impersonates Google Play Protect to deliver its payload, requests extensive permissions, can capture lockscreen credentials for device takeover, steals credentials from banking and cryptocurrency apps via screen overlays, harvests WhatsApp contact information, exfiltrates SMS messages, hijacks calls, logs keystrokes, replaces cryptocurrency wallet addresses in the clipboard, captures screenshots, and disables Google Play Protect while hiding its icon and muting device audio/vibration for stealth.
Android banking trojan that targets 217 banking and cryptocurrency apps. It is delivered via malicious websites masquerading as TikTok or Chrome, uses a dropper posing as Google Play Protect, abuses Accessibility Services, deploys fake overlays to steal credentials and card data, intercepts SMS, blocks incoming bank calls, disables Play Protect, captures screenshots, logs keystrokes and screen content, and swaps cryptocurrency wallet addresses via clipboard manipulation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.