Skip to content
Malware

Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials

A newly discovered Android banking trojan called Rokarolla has been making waves across the cybersecurity community, targeting victims by posing as well-known, trusted applications. The malware goes after banking and cryptocurrency users with a level of sophistication that puts it firmly in a differ...

· Jun 29, 2026 · 7 min read · 👁 1 views
Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials

A newly discovered Android banking trojan called Rokarolla has been making waves across the cybersecurity community, targeting victims by posing as well-known, trusted applications.

The malware goes after banking and cryptocurrency users with a level of sophistication that puts it firmly in a different category from typical mobile threats.

Security experts say it is one of the more complete mobile fraud platforms seen in the Android malware space so far this year.

Rokarolla spreads through malicious websites carefully designed to look like legitimate software download portals.

Victims are tricked into installing what appears to be a trusted app, including fake versions of TikTok, Google Chrome, and even Google Play Protect.

Once installed, the trojan silently requests deep system permissions, setting the stage for a wide range of data theft and fraud operations.

Researchers at PolySwarm, who shared a report with Cyber Security News (CSN), identified the malware and noted that Rokarolla targets at least 217 banking and cryptocurrency applications .

The malware exposes at least 137 operator commands, giving attackers a powerful and flexible toolkit for compromising victim devices . The scale and structure of its targeting list point clearly to a financially motivated operation designed to maximize opportunities for fraud.

Beyond stealing login credentials, the trojan collects device unlock PINs and passwords, intercepts SMS messages including one-time passcodes, and blocks fraud alert calls before victims ever see them.

Its ability to combine so many capabilities into a single package makes detection and response considerably harder. Users may have no idea their device has been compromised until serious financial damage has already been done.

The malware also supports multiple fallback command-and-control domains, meaning that even if investigators take down one server, the operation keeps running.

It can dynamically pull updated configurations from attacker infrastructure, keeping its phishing content and target list current. This kind of built-in resilience is a clear sign that the group behind Rokarolla planned for long-term, sustained campaigns.

Hackers Use Rokarolla Banking Trojan

Rokarolla’s most dangerous trick is its use of HTML-based phishing overlays that appear directly on top of legitimate banking and cryptocurrency applications.

When a user opens a targeted app, the malware instantly displays a fake login screen that looks nearly identical to the real one. Without close inspection, most users would simply type in their credentials, handing them straight to the attacker.

The malware also abuses Android Accessibility Services to automate actions, read on-screen content, and interact with apps without the user noticing.

This lets it silently log keystrokes, extract on-screen text, and harvest contact information from apps like WhatsApp.

Researchers noted that clipboard monitoring is also active, meaning the trojan can swap out a copied cryptocurrency wallet address with one controlled by the attacker before a transfer is confirmed .

SMS Interception and Device Surveillance Capabilities

One of the most alarming features of Rokarolla is its ability to intercept SMS messages in real time, capturing one-time passcodes that many banks and crypto platforms use for two-factor authentication.

By grabbing these codes the moment they arrive, attackers can bypass account security even when victims have extra protections turned on.

This makes it effective against services that many users once considered relatively safe. The malware takes periodic screenshots of the device and transmits them compressed to its control servers, allowing operators to visually monitor victim activity over time .

It can also block or intercept incoming phone calls, preventing banks from reaching customers with fraud warnings.

Security experts recommend avoiding app downloads from unofficial websites, exercising caution when granting Accessibility Service permissions, and monitoring your device for unexpected permission changes or unexplained battery drain .

Defenders are advised to watch closely for unauthorized Accessibility Service usage, suspicious overlay behavior, and unexpected SMS handler modifications as early warning signs.

Organizations managing mobile device fleets should treat any app sideloaded outside of official stores with serious scrutiny. Early detection remains the most effective line of defense against highly persistent threats like Rokarolla.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA-256890ecea4ebe4fea692ad36adf02abeb37c181cb7bdb6122cd52d9aaafe7d6cf3Rokarolla Android malware sample
SHA-2561ba364113c4cec5542d1b2c76d7c163a66bdf90bc373256d5178f880f9742960Rokarolla Android malware sample
SHA-256d7d960ef10b08c472ad397b6fd9e9481338b2077c7c2f44d3dc2c65b19345ae0Rokarolla Android malware sample
SHA-25657307ee8a3cda10730eacecaf789fab6f8771f9d29397e07c31a6bd4551bba10Rokarolla Android malware sample
SHA-2563fae7ede2ef9c809b54504c3d78e5111d7fad0b522c707b8f6ff21015af79251Rokarolla Android malware sample
SHA-256fe41e6c1725f63582f022a17abe098e49338a78118a00ca87785b2fa0cf3dadfRokarolla Android malware sample
SHA-256be8573971b85fda81a2fac27adb7a3a9b2cf7e1d9bdf713361a725324d378d34Rokarolla Android malware sample
SHA-2565139253b1f30b34ab3aa888aba175866fa1f82728ab07b999c24b49b191c3f68Rokarolla Android malware sample
SHA-25643888be8debbbd74012484d4e4f9a1c70c2ff3970e0bf499c9aebba9776930a1Rokarolla Android malware sample
SHA-256a5e6763b09553691c8b42deefb725fa3b8c133a03a34cea87740b1f13d08bac3Rokarolla Android malware sample
SHA-2561d3270a9141f8f16047799f1132633d72fd421b6c8f1878b5ef04ced6add4db8Rokarolla Android malware sample
SHA-25662aef76c2d1897203649844b45317d9e1723819479a2b88ca4b3290ca9f4c9f0Rokarolla Android malware sample
SHA-25648a3db92fac1ba9c218253576e09f42faabeaf48cf80663cf32e06b0a66e983dRokarolla Android malware sample
SHA-256726095e56c693977b7796dc7cead2e2a49551d77d3f442aaa28997615ba07e99Rokarolla Android malware sample
SHA-256c3cfe522d2da15b033f65eb5377bf9e99be598dc4c21729e6f168dbc8f19540bRokarolla Android malware sample
SHA-2563e25c28c5e93376683e841b7ad60f9383bb3bf831284a93a4aae798fc769d767Rokarolla Android malware sample
SHA-2568d65e4df0ad369f491698437413afd1bd55fff309860f9cdecc778c9ac062282Rokarolla Android malware sample
SHA-256c08cd3f78c0edcced6b1a694284b6ed4a9e0422f469e07c702c4a8d1f6c186f4Rokarolla Android malware sample
SHA-256696ef29f77a91aa91279c83088a07ab137d5049dc096ef862a35f9d890a552b3Rokarolla Android malware sample
SHA-2568ddbcebe1014a645855986e85b2c54ee167baf1e9a0d74179faf81a5ee6878f4Rokarolla Android malware sample
SHA-2561e4ed7e40608750cd0bfe96f5ed493a022b58ec54da2345336c522f7c78197afRokarolla Android malware sample
SHA-256c505353a6c58a21cb7b0343202e8629bee2f121f01c21dd8e0b61b7c55b77495Rokarolla Android malware sample
SHA-256aec2a36e8d68b23444348a7cec2d6ec287cb8810d1e190e04743645426ababb1Rokarolla Android malware sample
SHA-256f49be77b95cabd28d2dfe91786863576f6bd3f43a9d6de67a5b5851afe3aff9aRokarolla Android malware sample
SHA-256e76cbdf420540a18e2ddea02938acf3c4b4139f3511d314dca9781afe1e439bbRokarolla Android malware sample
SHA-256c3e324106803df27f5b6e0d49d2daf02d4cde396af4401f1ad29d78198e370b6Rokarolla Android malware sample
SHA-256ed036356fa2d3490d3ddb5ee7ae98bab80b505938f0199d9b10f12266f345896Rokarolla Android malware sample
SHA-256d6403ec82659eb62424bb1033615a8df27635080d02e438a4ee7e2334b1155f7Rokarolla Android malware sample
SHA-256c734a665f04eb9ab17047e65940fc35bad0221d59c2fc4fd0d170f2181514034Rokarolla Android malware sample
SHA-256e134cffcbe1fa8a861fd1f9a506f10ca5ff56cd5082360ef13d204676792e8bcRokarolla Android malware sample
SHA-256f0c18f045e3bb0193ef1169f5fa1abff7aa47e9a23da35cf67bbb9548a5e32c0Rokarolla Android malware sample
SHA-256f8cb375a4129358ad5881c29a6921fc1e5773028c0b31da83298f606118b185aRokarolla Android malware sample
SHA-2563c304a1ac73590aaf94b62711a5f2fd0cbb863dab13aef6ec1eb156f4a7bd5b9Rokarolla Android malware sample
SHA-2562eb80e5519fc6defcec8cc30a5cf4f75ee5ec8d2435759bb77c19826f1e20efbRokarolla Android malware sample
SHA-2561f4c70cb317ffd25adc828fbac3bb8f07739e23111f7b7905926489fe35f8973Rokarolla Android malware sample

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you