The images in this article were generated with artificial intelligence. How we publish
A new banking Trojan for Android, baptized as Rokarolla again shows that the line between a legitimate app and a critical financial security risk can be erased in seconds when a user installs software from unverified sources. Mobile researchers have described a campaign in which the threat is distributed through malicious websites that pretend to offer popular apps like Google Chrome or TikTok; they actually act as droppers that supplant Google Play Protect and then install the real malware.
Beyond the initial vector, Rokarolla stands out for its operational complexity: it operates with a set of 137 commands and verify the presence of up to 217 banking and cryptomoneda applications to download specific phishing templates. When the user opens a target app, the Trojan can overlap a false screen (overlay) to capture credentials, card information and authentication codes, and also uses overlay to read or capture the PIN / device unlocking pattern.

The use of the Accessibility API as a gateway to high privileges is central to this attack. Rokarolla requests Accessibility permissions, notifications, SMS and calls, and once granted it gets the ability to record keys, read and manipulate the clipboard, take regular screenshots with temporary seal, intercept and block incoming calls (including voice bank alerts or SMS) and keep the device in a state where the user does not suspect.
In addition to technical evasion - like disable Google Play Protect, hide the app icon, silence audio and keep the screen on - Rokarolla sends to the control and control server (C2) a device profile (model, Android version, battery, storage, memory, location) to generate a unique identifier per victim and adapt its behavior, which facilitates targeted and persistent campaigns.
The practical implications are serious: with access to SMS, notifications, calls and the ability to overlap interfaces, operators can intercept dual-factor SMS codes, block notifications from banks and present screens that simulate exactly the process of login or transaction approval. This drastically reduces the effectiveness of SMS-based or simple screen confirmations.
For private users, the first rule of defence is clear: avoid installing APKS outside Google Play unless the source is absolutely reliable. Google Play is not infallible, but it is an initial filter; the risk increases significantly with external sites and links that promise popular apps in "unofficial" versions. You can review information about Play Protect in Google Play Protect documentation.
If you suspect that your phone may be compromised, immediately review the Accessibility settings and applications with administrator's permissions, and revoke any suspicious permissions. If an app refuses to disinstall or persists in strange behaviors (missing notifications, display showing ghost facilities, clipboard changes), it is wise to isolate the device and consider a safe backup followed by a factory re-establishment. The response centres and official guides offer practical recommendations on mobile security; see, for example, the recommendations of the US government. United States CISA.

In the corporate area and for users with sensitive accounts, it is appropriate to migrate authentication mechanisms to factors that do not depend on SMS (authentication apps, hardware keys), activate email alerts and off-the-phone notifications where possible, and apply application of app installation blocking policies from unknown origins. Organizations should strengthen their MDM / EMM controls, restrict Accessibility permits and monitor exfiltration signals or abnormal behaviors in mobile endpoints.
Security specialists can deepen the set of commands and commitment indicators published by researchers; for example, there is a repository with the 137 commands analyzed to identify technical signals and create detection rules: GitHub - Zimperium: Rokarolla commands. Implementing EDR / Mobile-EDR rules that detect unusual requests for Accessibility permits, overlay activity and C2 connections is key to stopping similar campaigns.
Finally, keeping the operating system up to date, using mobile security solutions from recognized suppliers and distrusting urgent requests to grant permits or install applications that "correct" phone problems are simple measures that significantly reduce risk. In a scenario where attackers can almost completely control a device by relatively well-known techniques, prevention and rapid response remain the most effective defense.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...