New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Rokarolla, a new Android banking trojan, targets 217 financial apps and uses 137 remote commands to steal PINs, SMS codes, and cryptocurrency funds. It also disables Google Play protections and manipulates clipboard data to hijack crypto transactions.
Rokarolla's extensive capabilities demand immediate attention from both app developers and users. Implementing multi-factor authentication and monitoring clipboard activity could mitigate risks. Enterprises should consider endpoint detection solutions for mobile devices.
The Rokarolla malware, discovered by Zimperium's zLabs, is a sophisticated Android banking trojan targeting both banking and cryptocurrency apps. Its arsenal includes 137 remote commands, enabling attackers to take full control of infected devices.
Rokarolla can steal lock-screen PINs, intercept and send SMS codes, and manipulate clipboard data to redirect cryptocurrency transactions. It also disables Google Play protections, leaving devices vulnerable to further exploitation.
With its ability to compromise 217 apps, Rokarolla poses a significant threat to financial security. Users are advised to avoid sideloading apps, enable multi-factor authentication, and monitor financial transactions closely for unusual activity.