Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft August 2026 Patch Tuesday fixes 394 flaws, including 3 zero-days
August 11, 2026
Critical Zoom Zero-Click Flaws Let Attackers Hijack User Devices
August 11, 2026
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Home/Threats/Rokarolla Android Malware Disables Play Protect, Seizes Device Control
Threats

Rokarolla Android Malware Disables Play Protect, Seizes Device Control

Key Takeaways Rokarolla is a recently discovered Android banking trojan capable of disabling Google Play Protect and achieving full device takeover. The malware spreads through deceptive websites,...

Emy Elsamnoudy
Emy Elsamnoudy
June 17, 2026 4 Min Read
57 0

Key Takeaways

  • Rokarolla is a recently discovered Android banking trojan capable of disabling Google Play Protect and achieving full device takeover.
  • The malware spreads through deceptive websites, impersonating popular applications like TikTok and Google Chrome to trick users into downloading it.
  • Once installed, Rokarolla uses Android Accessibility Services to steal credentials, intercept SMS, log keystrokes, and monitor screen activity, targeting over 217 financial applications.
  • It employs advanced stealth techniques, including hiding its icon, muting notifications, and maintaining an active screen state to avoid detection and ensure uninterrupted malicious operations.
  • Users are advised to avoid third-party app stores, exercise caution with app permissions, and maintain updated security measures to mitigate the risk of infection.

Android Banking Trojan Rokarolla Bypasses Play Protect, Achieves Full Device Control

A sophisticated new Android banking trojan, dubbed Rokarolla, has emerged, posing a significant threat to mobile users. This malware distinguishes itself by its ability to neutralize Google’s native Play Protect security feature and subsequently seize complete control over compromised devices, according to a recent security analysis.

Table Of Content

  • Key Takeaways
  • Android Banking Trojan Rokarolla Bypasses Play Protect, Achieves Full Device Control
  • Infection Vector and Stealth Mechanisms
  • Advanced Control and Data Exfiltration
  • Silent Data Theft and Resilient C2 Infrastructure
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The Rokarolla malware is engineered for covert operation, ensuring it remains undetected by the user while executing a full device takeover. Its extensive targeting capabilities are alarming, with over 217 banking and cryptocurrency applications currently within its malicious scope.

Infection Vector and Stealth Mechanisms

Rokarolla propagates primarily through fraudulent websites designed to deceive users into downloading what appears to be a legitimate application. The malware cleverly masquerades as widely used apps such as TikTok or Google Chrome, making it easy for unsuspecting individuals to install it without suspicion. Upon successful installation, a dropper component discreetly deploys the primary malicious payload in the background.

Researchers at Zimperium’s zLabs team uncovered this threat through rigorous technical analysis, detailing their findings in a report shared with Cyber Security News (CSN). The trojan derives its name from its own command and control (C2) infrastructure, providing a unique identifier for tracking. The research team identified that the malware utilizes 137 distinct commands to orchestrate its activities on infected devices.

The operational scope of Rokarolla is extensive and concerning, even for experienced cybersecurity professionals. It can capture lock screen PINs and passwords using deceptive overlays, silently read all SMS messages, and meticulously log every keystroke performed on the device. All harvested data is then exfiltrated to attacker-controlled servers without the victim’s knowledge.

A particularly alarming characteristic of this trojan is its aggressive methodology for concealing its presence. It removes its application icon from the device’s app drawer, silences all sounds and vibrations to prevent users from noticing bank alert notifications, and forces the screen to remain active, ensuring its automated malicious tasks are not interrupted. This level of stealth represents a severe risk for individuals with sensitive financial applications on their smartphones.

Advanced Control and Data Exfiltration

Rokarolla’s initial move after infection is to dismantle Android’s built-in security defenses. It employs specific commands, including disable_google_play and protectorgoogle_disable, to deactivate Google Play Protect. This effectively leaves the device vulnerable and opens a clear path for the malware to execute its full array of malicious functions.

The trojan exploits Android’s Accessibility Services, a feature typically designed to assist users with disabilities, to interact with the device’s user interface on behalf of the attacker. It meticulously maps out UI elements, monitors active applications, and injects convincing fake login pages over legitimate banking applications to steal credentials. Users inadvertently provide their login details directly to the attackers, believing they are accessing their bank accounts.

Furthermore, Rokarolla utilizes a snapshot-based screen monitoring technique rather than conventional live screen casting. It captures screenshots at regular intervals, compresses them, and transmits them with timestamps to remote servers. This method provides attackers with a near real-time visual feed of all activities occurring on the victim’s device.

Silent Data Theft and Resilient C2 Infrastructure

Rokarolla’s capabilities extend beyond credential theft to encompass a wide range of sensitive data exfiltration. It intercepts SMS messages, crucial for capturing one-time passwords (OTPs) from banks, blocks incoming calls from financial institutions, and silently manipulates clipboard content to redirect cryptocurrency wallet addresses. This allows attackers to reroute financial transactions without the user ever detecting the alteration.

The malware communicates with its command and control (C2) servers via HTTPS, enabling it to blend in with normal network traffic. Upon initial contact, it transmits a comprehensive device profile, including hardware specifications, battery status, and storage information, to generate a unique bot ID. The sophisticated C2 infrastructure also incorporates multiple fallback domains, allowing the malware to dynamically switch between them if a primary domain is blocked or taken down.

What You Should Do

  • Avoid Third-Party App Stores: Only download applications from the official Google Play Store. Unofficial sources are frequently used to distribute malware.
  • Exercise Caution with Permissions: Be extremely wary of applications requesting Accessibility Service permissions, especially if they are not legitimate accessibility tools. Review all requested permissions carefully before granting them.
  • Keep Software Updated: Ensure your Android operating system and all applications are regularly updated to benefit from the latest security patches.
  • Utilize Mobile Threat Defense (MTD): Consider installing a reputable mobile threat defense solution to provide an additional layer of security against sophisticated malware like Rokarolla.
  • Be Skeptical of Phishing: Remain vigilant against phishing attempts via email or SMS that prompt you to download applications from unfamiliar websites.

Indicators of Compromise (IoCs):-

The following IoCs were identified in the Zimperium zLabs research report.

Type Indicator Description
URL hxxps[://]infocontablidades[.]it[.]com/ Primary malware distribution site masquerading as TikTok or Google Chrome
Domain beralisvc[.]info C2 fallback domain used for malware communication
Domain blestorians[.]cfd C2 fallback domain used for malware communication
Domain abiorime[.]cfd C2 fallback domain used for malware communication
Domain morevoms[.]cfd C2 fallback domain used for malware communication

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityHackerMalwarePatchSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Threat Actors Leverage OpenAI Codex and Claude for Exploitation and Data Exfiltration

Next Post

Critical Flaw in Deno-Based RAT Impersonates Microsoft Teams, Mailbombs Employees

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us