A newly discovered Android banking trojan called Rokarolla has been making waves across the cybersecurity community, targeting victims by posing as well-known, trusted applications.
The malware goes after banking and cryptocurrency users with a level of sophistication that puts it firmly in a different category from typical mobile threats.
Security experts say it is one of the more complete mobile fraud platforms seen in the Android malware space so far this year.
Rokarolla spreads through malicious websites carefully designed to look like legitimate software download portals.
Victims are tricked into installing what appears to be a trusted app, including fake versions of TikTok, Google Chrome, and even Google Play Protect.
Once installed, the trojan silently requests deep system permissions, setting the stage for a wide range of data theft and fraud operations.
Researchers at PolySwarm, who shared a report with Cyber Security News (CSN), identified the malware and noted that Rokarolla targets at least 217 banking and cryptocurrency applications .
The malware exposes at least 137 operator commands, giving attackers a powerful and flexible toolkit for compromising victim devices . The scale and structure of its targeting list point clearly to a financially motivated operation designed to maximize opportunities for fraud.
Beyond stealing login credentials, the trojan collects device unlock PINs and passwords, intercepts SMS messages including one-time passcodes, and blocks fraud alert calls before victims ever see them.
Its ability to combine so many capabilities into a single package makes detection and response considerably harder. Users may have no idea their device has been compromised until serious financial damage has already been done.
The malware also supports multiple fallback command-and-control domains, meaning that even if investigators take down one server, the operation keeps running.
It can dynamically pull updated configurations from attacker infrastructure, keeping its phishing content and target list current. This kind of built-in resilience is a clear sign that the group behind Rokarolla planned for long-term, sustained campaigns.
Hackers Use Rokarolla Banking Trojan
Rokarolla’s most dangerous trick is its use of HTML-based phishing overlays that appear directly on top of legitimate banking and cryptocurrency applications.
When a user opens a targeted app, the malware instantly displays a fake login screen that looks nearly identical to the real one. Without close inspection, most users would simply type in their credentials, handing them straight to the attacker.
The malware also abuses Android Accessibility Services to automate actions, read on-screen content, and interact with apps without the user noticing.
This lets it silently log keystrokes, extract on-screen text, and harvest contact information from apps like WhatsApp.
Researchers noted that clipboard monitoring is also active, meaning the trojan can swap out a copied cryptocurrency wallet address with one controlled by the attacker before a transfer is confirmed .
SMS Interception and Device Surveillance Capabilities
One of the most alarming features of Rokarolla is its ability to intercept SMS messages in real time, capturing one-time passcodes that many banks and crypto platforms use for two-factor authentication.
By grabbing these codes the moment they arrive, attackers can bypass account security even when victims have extra protections turned on.
This makes it effective against services that many users once considered relatively safe. The malware takes periodic screenshots of the device and transmits them compressed to its control servers, allowing operators to visually monitor victim activity over time .
It can also block or intercept incoming phone calls, preventing banks from reaching customers with fraud warnings.
Security experts recommend avoiding app downloads from unofficial websites, exercising caution when granting Accessibility Service permissions, and monitoring your device for unexpected permission changes or unexplained battery drain .
Defenders are advised to watch closely for unauthorized Accessibility Service usage, suspicious overlay behavior, and unexpected SMS handler modifications as early warning signs.
Organizations managing mobile device fleets should treat any app sideloaded outside of official stores with serious scrutiny. Early detection remains the most effective line of defense against highly persistent threats like Rokarolla.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 890ecea4ebe4fea692ad36adf02abeb37c181cb7bdb6122cd52d9aaafe7d6cf3 |
Rokarolla Android malware sample |
| SHA-256 | 1ba364113c4cec5542d1b2c76d7c163a66bdf90bc373256d5178f880f9742960 |
Rokarolla Android malware sample |
| SHA-256 | d7d960ef10b08c472ad397b6fd9e9481338b2077c7c2f44d3dc2c65b19345ae0 |
Rokarolla Android malware sample |
| SHA-256 | 57307ee8a3cda10730eacecaf789fab6f8771f9d29397e07c31a6bd4551bba10 |
Rokarolla Android malware sample |
| SHA-256 | 3fae7ede2ef9c809b54504c3d78e5111d7fad0b522c707b8f6ff21015af79251 |
Rokarolla Android malware sample |
| SHA-256 | fe41e6c1725f63582f022a17abe098e49338a78118a00ca87785b2fa0cf3dadf |
Rokarolla Android malware sample |
| SHA-256 | be8573971b85fda81a2fac27adb7a3a9b2cf7e1d9bdf713361a725324d378d34 |
Rokarolla Android malware sample |
| SHA-256 | 5139253b1f30b34ab3aa888aba175866fa1f82728ab07b999c24b49b191c3f68 |
Rokarolla Android malware sample |
| SHA-256 | 43888be8debbbd74012484d4e4f9a1c70c2ff3970e0bf499c9aebba9776930a1 |
Rokarolla Android malware sample |
| SHA-256 | a5e6763b09553691c8b42deefb725fa3b8c133a03a34cea87740b1f13d08bac3 |
Rokarolla Android malware sample |
| SHA-256 | 1d3270a9141f8f16047799f1132633d72fd421b6c8f1878b5ef04ced6add4db8 |
Rokarolla Android malware sample |
| SHA-256 | 62aef76c2d1897203649844b45317d9e1723819479a2b88ca4b3290ca9f4c9f0 |
Rokarolla Android malware sample |
| SHA-256 | 48a3db92fac1ba9c218253576e09f42faabeaf48cf80663cf32e06b0a66e983d |
Rokarolla Android malware sample |
| SHA-256 | 726095e56c693977b7796dc7cead2e2a49551d77d3f442aaa28997615ba07e99 |
Rokarolla Android malware sample |
| SHA-256 | c3cfe522d2da15b033f65eb5377bf9e99be598dc4c21729e6f168dbc8f19540b |
Rokarolla Android malware sample |
| SHA-256 | 3e25c28c5e93376683e841b7ad60f9383bb3bf831284a93a4aae798fc769d767 |
Rokarolla Android malware sample |
| SHA-256 | 8d65e4df0ad369f491698437413afd1bd55fff309860f9cdecc778c9ac062282 |
Rokarolla Android malware sample |
| SHA-256 | c08cd3f78c0edcced6b1a694284b6ed4a9e0422f469e07c702c4a8d1f6c186f4 |
Rokarolla Android malware sample |
| SHA-256 | 696ef29f77a91aa91279c83088a07ab137d5049dc096ef862a35f9d890a552b3 |
Rokarolla Android malware sample |
| SHA-256 | 8ddbcebe1014a645855986e85b2c54ee167baf1e9a0d74179faf81a5ee6878f4 |
Rokarolla Android malware sample |
| SHA-256 | 1e4ed7e40608750cd0bfe96f5ed493a022b58ec54da2345336c522f7c78197af |
Rokarolla Android malware sample |
| SHA-256 | c505353a6c58a21cb7b0343202e8629bee2f121f01c21dd8e0b61b7c55b77495 |
Rokarolla Android malware sample |
| SHA-256 | aec2a36e8d68b23444348a7cec2d6ec287cb8810d1e190e04743645426ababb1 |
Rokarolla Android malware sample |
| SHA-256 | f49be77b95cabd28d2dfe91786863576f6bd3f43a9d6de67a5b5851afe3aff9a |
Rokarolla Android malware sample |
| SHA-256 | e76cbdf420540a18e2ddea02938acf3c4b4139f3511d314dca9781afe1e439bb |
Rokarolla Android malware sample |
| SHA-256 | c3e324106803df27f5b6e0d49d2daf02d4cde396af4401f1ad29d78198e370b6 |
Rokarolla Android malware sample |
| SHA-256 | ed036356fa2d3490d3ddb5ee7ae98bab80b505938f0199d9b10f12266f345896 |
Rokarolla Android malware sample |
| SHA-256 | d6403ec82659eb62424bb1033615a8df27635080d02e438a4ee7e2334b1155f7 |
Rokarolla Android malware sample |
| SHA-256 | c734a665f04eb9ab17047e65940fc35bad0221d59c2fc4fd0d170f2181514034 |
Rokarolla Android malware sample |
| SHA-256 | e134cffcbe1fa8a861fd1f9a506f10ca5ff56cd5082360ef13d204676792e8bc |
Rokarolla Android malware sample |
| SHA-256 | f0c18f045e3bb0193ef1169f5fa1abff7aa47e9a23da35cf67bbb9548a5e32c0 |
Rokarolla Android malware sample |
| SHA-256 | f8cb375a4129358ad5881c29a6921fc1e5773028c0b31da83298f606118b185a |
Rokarolla Android malware sample |
| SHA-256 | 3c304a1ac73590aaf94b62711a5f2fd0cbb863dab13aef6ec1eb156f4a7bd5b9 |
Rokarolla Android malware sample |
| SHA-256 | 2eb80e5519fc6defcec8cc30a5cf4f75ee5ec8d2435759bb77c19826f1e20efb |
Rokarolla Android malware sample |
| SHA-256 | 1f4c70cb317ffd25adc828fbac3bb8f07739e23111f7b7905926489fe35f8973 |
Rokarolla Android malware sample |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Upgrade your proactive defense against attacks. Access 5 proven threat hunting tactics you can deploy in your SOC.
The post Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials appeared first on Cyber Security News.
​The original article found on Cyber Security News Read More