Categorie: News

A new Android Trojan targets 217 banking apps: steals PINs, SMS codes, and crypto wallets

Cybersecurity researchers from the zLabs team of Zimperium have identified a new and sophisticated threat: a banking Trojan for Android devices capable of taking near-total control of infected smartphones.

Nicknamed Rokarolla, after the criminals’ command-and-control infrastructure, this malware targets as many as 217 financial applications, including traditional banking services and cryptocurrency management platforms.

With an arsenal of 137 remotely executable commands, the malicious code surpasses in complexity even recent threats such as the HOOK trojan, which stopped at 107 instructions.

Rokarolla is the new Trojan that drains your bank account

Credits: Canva

Rokarolla spreads through malicious websites that pose as legitimate versions of very popular apps, such as TikTok or the Google Chrome browser.

The first component the victim downloads is an installer masquerading as Google Play Protect.

Taking advantage of this clever disguise, the malware tricks the user into granting the operating system’s Accessibility permissions. Once installed and operational, the Trojan’s first step is precisely to disable the real protection of Google Play Protect, depriving the device of its main built-in automatic defense.

The financial theft mechanism orchestrated by the Rokarolla developers relies mainly on the use of overlay screens. The trojan downloads from its server an updated list of targets and, for each banking app or digital wallet detected as active on the smartphone, stores in a local database a fake login page in HTML format.

The moment the user opens the legitimate banking app, the malware instantly overlays the fake page. Any information entered on this screen, including credit card details and login credentials, is immediately captured and transmitted to the attackers.

A second fake screen is used to perfectly replicate the native Android lock screen. This ploy allows criminals to record the PIN, the unlock sequence, or the device password, giving remote operators the ability to send commands and navigate the system even when the smartphone is physically locked by the owner.

Total surveillance and manipulation of transactions

The malware’s spying capabilities are extensive. It acts as a keylogger to record every keystroke on the on-screen keyboard and systematically reads all incoming notifications.

Moreover, it has full access to SMS messages: it can read incoming messages and send new ones without any manual intervention. This function is crucial for intercepting one-time codes banks send to authorize payments or new logins.

Becoming the default handler for messages and calls, the Trojan is even able to block incoming calls, effectively preventing the bank’s anti-fraud alerts from reaching the victim.

A equally grave danger concerns those handling cryptocurrency assets. The malware silently analyzes and rewrites the OS clipboard. If the user copies the address of a digital wallet to make a payment, Rokarolla replaces it in a fraction of a second with a destination address controlled by the criminals, diverting funds irreversibly to illicit accounts.

To visually monitor the victim’s behavior without arousing suspicion, the trojan avoids traditional video transmission methods that would show a recording icon in the status bar. Instead, it uses Accessibility permissions to take continuous screenshots, compressing them into PNG format and sending them to the servers one frame at a time, operating in absolute silence.

Resilient Architecture and Security Measures

The network infrastructure supporting Rokarolla is designed to withstand attempts to dismantle by authorities.

The malware keeps multiple emergency domains active for command-and-control operations and can receive new ones in real time. Consequently, taking down a single server is totally ineffective at stopping the fraudulent campaign.

Although Zimperium has not yet formally attributed the attack to a specific group of cybercriminals, the technical setup shows a notable level of sophistication.

Being an active infection rather than an intrinsic vulnerability of the underlying software, there is no automatic patch able to resolve the problem.

Protection rests exclusively on the users’ preventive discipline: install applications only from the official Google Play Store, constantly verify that Play Protect is enabled, and consider any unexpected request for Accessibility services access as a sign of compromise, because it is exactly that authorization that triggers and sustains the entire attack cycle.

Luca Zaninello

Appassionato del mondo della telefonia da sempre, da oltre un decennio si occupa di provare con mano i prodotti e di raccontare le sue esperienze al pubblico del web. Fotografo amatoriale, ha un occhio di riguardo per i cameraphone più esagerati.

Recent Posts

The most invasive apps for privacy: Meta has five in the top 10, Instagram and Facebook leading

The weight of each data item depends on how it is processed. The most invasive…

9 hours ago

WhatsApp will remind you of your contacts’ birthdays

WhatsApp is getting ready to change, and in the latest beta versions new details about…

10 hours ago

Does Spotify take up too much space on your phone? A new feature could solve the problem

To make playback smoother and use less data when re-listening to a track, Spotify stores…

10 hours ago

iPhone 18 Pro and Pro Max Face ID issues: Apple prepares a fix

An attempted unlock withFace ID failed can be enough to crash the iPhone 18 Pro.…

11 hours ago

Galaxy Buds On: here are Samsung’s first clip-on earbuds

There should also be support for voice assistants, accessible directly from the earbuds. Samsung has…

11 hours ago

eBay: How Authenticity Verification Works, Now Available in Italy

Bags, sneakers and luxury watches sold on eBay can pass through the hands of an…

12 hours ago