Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials

Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials

A newly discovered Android banking trojan called Rokarolla has been making waves across the cybersecurity community, targeting victims by posing as well-known, trusted applications.

The malware goes after banking and cryptocurrency users with a level of sophistication that puts it firmly in a different category from typical mobile threats.

Security experts say it is one of the more complete mobile fraud platforms seen in the Android malware space so far this year.

Rokarolla spreads through malicious websites carefully designed to look like legitimate software download portals.

Victims are tricked into installing what appears to be a trusted app, including fake versions of TikTok, Google Chrome, and even Google Play Protect.

Once installed, the trojan silently requests deep system permissions, setting the stage for a wide range of data theft and fraud operations.

Researchers at PolySwarm, who shared a report with Cyber Security News (CSN), identified the malware and noted that Rokarolla targets at least 217 banking and cryptocurrency applications .

The malware exposes at least 137 operator commands, giving attackers a powerful and flexible toolkit for compromising victim devices . The scale and structure of its targeting list point clearly to a financially motivated operation designed to maximize opportunities for fraud.

Beyond stealing login credentials, the trojan collects device unlock PINs and passwords, intercepts SMS messages including one-time passcodes, and blocks fraud alert calls before victims ever see them.

Its ability to combine so many capabilities into a single package makes detection and response considerably harder. Users may have no idea their device has been compromised until serious financial damage has already been done.

The malware also supports multiple fallback command-and-control domains, meaning that even if investigators take down one server, the operation keeps running.

It can dynamically pull updated configurations from attacker infrastructure, keeping its phishing content and target list current. This kind of built-in resilience is a clear sign that the group behind Rokarolla planned for long-term, sustained campaigns.

Hackers Use Rokarolla Banking Trojan

Rokarolla’s most dangerous trick is its use of HTML-based phishing overlays that appear directly on top of legitimate banking and cryptocurrency applications.

When a user opens a targeted app, the malware instantly displays a fake login screen that looks nearly identical to the real one. Without close inspection, most users would simply type in their credentials, handing them straight to the attacker.

The malware also abuses Android Accessibility Services to automate actions, read on-screen content, and interact with apps without the user noticing.

This lets it silently log keystrokes, extract on-screen text, and harvest contact information from apps like WhatsApp.

Researchers noted that clipboard monitoring is also active, meaning the trojan can swap out a copied cryptocurrency wallet address with one controlled by the attacker before a transfer is confirmed .

SMS Interception and Device Surveillance Capabilities

One of the most alarming features of Rokarolla is its ability to intercept SMS messages in real time, capturing one-time passcodes that many banks and crypto platforms use for two-factor authentication.

By grabbing these codes the moment they arrive, attackers can bypass account security even when victims have extra protections turned on.

This makes it effective against services that many users once considered relatively safe. The malware takes periodic screenshots of the device and transmits them compressed to its control servers, allowing operators to visually monitor victim activity over time .

It can also block or intercept incoming phone calls, preventing banks from reaching customers with fraud warnings.

Security experts recommend avoiding app downloads from unofficial websites, exercising caution when granting Accessibility Service permissions, and monitoring your device for unexpected permission changes or unexplained battery drain .

Defenders are advised to watch closely for unauthorized Accessibility Service usage, suspicious overlay behavior, and unexpected SMS handler modifications as early warning signs.

Organizations managing mobile device fleets should treat any app sideloaded outside of official stores with serious scrutiny. Early detection remains the most effective line of defense against highly persistent threats like Rokarolla.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 890ecea4ebe4fea692ad36adf02abeb37c181cb7bdb6122cd52d9aaafe7d6cf3 Rokarolla Android malware sample
SHA-256 1ba364113c4cec5542d1b2c76d7c163a66bdf90bc373256d5178f880f9742960 Rokarolla Android malware sample
SHA-256 d7d960ef10b08c472ad397b6fd9e9481338b2077c7c2f44d3dc2c65b19345ae0 Rokarolla Android malware sample
SHA-256 57307ee8a3cda10730eacecaf789fab6f8771f9d29397e07c31a6bd4551bba10 Rokarolla Android malware sample
SHA-256 3fae7ede2ef9c809b54504c3d78e5111d7fad0b522c707b8f6ff21015af79251 Rokarolla Android malware sample
SHA-256 fe41e6c1725f63582f022a17abe098e49338a78118a00ca87785b2fa0cf3dadf Rokarolla Android malware sample
SHA-256 be8573971b85fda81a2fac27adb7a3a9b2cf7e1d9bdf713361a725324d378d34 Rokarolla Android malware sample
SHA-256 5139253b1f30b34ab3aa888aba175866fa1f82728ab07b999c24b49b191c3f68 Rokarolla Android malware sample
SHA-256 43888be8debbbd74012484d4e4f9a1c70c2ff3970e0bf499c9aebba9776930a1 Rokarolla Android malware sample
SHA-256 a5e6763b09553691c8b42deefb725fa3b8c133a03a34cea87740b1f13d08bac3 Rokarolla Android malware sample
SHA-256 1d3270a9141f8f16047799f1132633d72fd421b6c8f1878b5ef04ced6add4db8 Rokarolla Android malware sample
SHA-256 62aef76c2d1897203649844b45317d9e1723819479a2b88ca4b3290ca9f4c9f0 Rokarolla Android malware sample
SHA-256 48a3db92fac1ba9c218253576e09f42faabeaf48cf80663cf32e06b0a66e983d Rokarolla Android malware sample
SHA-256 726095e56c693977b7796dc7cead2e2a49551d77d3f442aaa28997615ba07e99 Rokarolla Android malware sample
SHA-256 c3cfe522d2da15b033f65eb5377bf9e99be598dc4c21729e6f168dbc8f19540b Rokarolla Android malware sample
SHA-256 3e25c28c5e93376683e841b7ad60f9383bb3bf831284a93a4aae798fc769d767 Rokarolla Android malware sample
SHA-256 8d65e4df0ad369f491698437413afd1bd55fff309860f9cdecc778c9ac062282 Rokarolla Android malware sample
SHA-256 c08cd3f78c0edcced6b1a694284b6ed4a9e0422f469e07c702c4a8d1f6c186f4 Rokarolla Android malware sample
SHA-256 696ef29f77a91aa91279c83088a07ab137d5049dc096ef862a35f9d890a552b3 Rokarolla Android malware sample
SHA-256 8ddbcebe1014a645855986e85b2c54ee167baf1e9a0d74179faf81a5ee6878f4 Rokarolla Android malware sample
SHA-256 1e4ed7e40608750cd0bfe96f5ed493a022b58ec54da2345336c522f7c78197af Rokarolla Android malware sample
SHA-256 c505353a6c58a21cb7b0343202e8629bee2f121f01c21dd8e0b61b7c55b77495 Rokarolla Android malware sample
SHA-256 aec2a36e8d68b23444348a7cec2d6ec287cb8810d1e190e04743645426ababb1 Rokarolla Android malware sample
SHA-256 f49be77b95cabd28d2dfe91786863576f6bd3f43a9d6de67a5b5851afe3aff9a Rokarolla Android malware sample
SHA-256 e76cbdf420540a18e2ddea02938acf3c4b4139f3511d314dca9781afe1e439bb Rokarolla Android malware sample
SHA-256 c3e324106803df27f5b6e0d49d2daf02d4cde396af4401f1ad29d78198e370b6 Rokarolla Android malware sample
SHA-256 ed036356fa2d3490d3ddb5ee7ae98bab80b505938f0199d9b10f12266f345896 Rokarolla Android malware sample
SHA-256 d6403ec82659eb62424bb1033615a8df27635080d02e438a4ee7e2334b1155f7 Rokarolla Android malware sample
SHA-256 c734a665f04eb9ab17047e65940fc35bad0221d59c2fc4fd0d170f2181514034 Rokarolla Android malware sample
SHA-256 e134cffcbe1fa8a861fd1f9a506f10ca5ff56cd5082360ef13d204676792e8bc Rokarolla Android malware sample
SHA-256 f0c18f045e3bb0193ef1169f5fa1abff7aa47e9a23da35cf67bbb9548a5e32c0 Rokarolla Android malware sample
SHA-256 f8cb375a4129358ad5881c29a6921fc1e5773028c0b31da83298f606118b185a Rokarolla Android malware sample
SHA-256 3c304a1ac73590aaf94b62711a5f2fd0cbb863dab13aef6ec1eb156f4a7bd5b9 Rokarolla Android malware sample
SHA-256 2eb80e5519fc6defcec8cc30a5cf4f75ee5ec8d2435759bb77c19826f1e20efb Rokarolla Android malware sample
SHA-256 1f4c70cb317ffd25adc828fbac3bb8f07739e23111f7b7905926489fe35f8973 Rokarolla Android malware sample

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Upgrade your proactive defense against attacks. Access 5 proven threat hunting tactics you can deploy in your SOC.

The post Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials appeared first on Cyber Security News.

​The original article found on Cyber Security News Read More