New Rokarolla Android Trojan Found Targeting 217 Crypto and Banking Apps

https://hackread.com/wp-content/uploads/2026/06/rokarolla-android-trojan-crypto-and-banking-apps-1024x568.png

The zLabs research team at mobile security firm Zimperium has identified a new Android banking trojan named Rokarolla. This highly invasive malware is named after its command-and-control infrastructure (the server network that threat actors use to send instructions to infected phones).

According to zLabs researchers, this trojan is unusual in that it combines financial fraud with total device surveillance and can target 217 different cryptocurrency and banking programs.

Attack chain explained

The attack chain begins when a user visits a malicious website like infocontablidades.it.com. These pages actually contain the malware, hidden inside files that look like popular programs such as TikTok or Google Chrome.

When a victim downloads this file, a secondary dropper (secondary malware) runs first, disguised as a Google Play Protect security tool. It is this dropper that tricks the user into installing the final malicious payload.

Once installed, the malware asks for permission to use Android...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE