Rokarolla Android Malware Disables Play Protect, Seizes Device Control
Key Takeaways Rokarolla is a recently discovered Android banking trojan capable of disabling Google Play Protect and achieving full device takeover. The malware spreads through deceptive websites,...
Key Takeaways
- Rokarolla is a recently discovered Android banking trojan capable of disabling Google Play Protect and achieving full device takeover.
- The malware spreads through deceptive websites, impersonating popular applications like TikTok and Google Chrome to trick users into downloading it.
- Once installed, Rokarolla uses Android Accessibility Services to steal credentials, intercept SMS, log keystrokes, and monitor screen activity, targeting over 217 financial applications.
- It employs advanced stealth techniques, including hiding its icon, muting notifications, and maintaining an active screen state to avoid detection and ensure uninterrupted malicious operations.
- Users are advised to avoid third-party app stores, exercise caution with app permissions, and maintain updated security measures to mitigate the risk of infection.
Android Banking Trojan Rokarolla Bypasses Play Protect, Achieves Full Device Control
A sophisticated new Android banking trojan, dubbed Rokarolla, has emerged, posing a significant threat to mobile users. This malware distinguishes itself by its ability to neutralize Google’s native Play Protect security feature and subsequently seize complete control over compromised devices, according to a recent security analysis.
Table Of Content
The Rokarolla malware is engineered for covert operation, ensuring it remains undetected by the user while executing a full device takeover. Its extensive targeting capabilities are alarming, with over 217 banking and cryptocurrency applications currently within its malicious scope.
Infection Vector and Stealth Mechanisms
Rokarolla propagates primarily through fraudulent websites designed to deceive users into downloading what appears to be a legitimate application. The malware cleverly masquerades as widely used apps such as TikTok or Google Chrome, making it easy for unsuspecting individuals to install it without suspicion. Upon successful installation, a dropper component discreetly deploys the primary malicious payload in the background.
Researchers at Zimperium’s zLabs team uncovered this threat through rigorous technical analysis, detailing their findings in a report shared with Cyber Security News (CSN). The trojan derives its name from its own command and control (C2) infrastructure, providing a unique identifier for tracking. The research team identified that the malware utilizes 137 distinct commands to orchestrate its activities on infected devices.
The operational scope of Rokarolla is extensive and concerning, even for experienced cybersecurity professionals. It can capture lock screen PINs and passwords using deceptive overlays, silently read all SMS messages, and meticulously log every keystroke performed on the device. All harvested data is then exfiltrated to attacker-controlled servers without the victim’s knowledge.
A particularly alarming characteristic of this trojan is its aggressive methodology for concealing its presence. It removes its application icon from the device’s app drawer, silences all sounds and vibrations to prevent users from noticing bank alert notifications, and forces the screen to remain active, ensuring its automated malicious tasks are not interrupted. This level of stealth represents a severe risk for individuals with sensitive financial applications on their smartphones.
Advanced Control and Data Exfiltration
Rokarolla’s initial move after infection is to dismantle Android’s built-in security defenses. It employs specific commands, including disable_google_play and protectorgoogle_disable, to deactivate Google Play Protect. This effectively leaves the device vulnerable and opens a clear path for the malware to execute its full array of malicious functions.
The trojan exploits Android’s Accessibility Services, a feature typically designed to assist users with disabilities, to interact with the device’s user interface on behalf of the attacker. It meticulously maps out UI elements, monitors active applications, and injects convincing fake login pages over legitimate banking applications to steal credentials. Users inadvertently provide their login details directly to the attackers, believing they are accessing their bank accounts.
Furthermore, Rokarolla utilizes a snapshot-based screen monitoring technique rather than conventional live screen casting. It captures screenshots at regular intervals, compresses them, and transmits them with timestamps to remote servers. This method provides attackers with a near real-time visual feed of all activities occurring on the victim’s device.
Silent Data Theft and Resilient C2 Infrastructure
Rokarolla’s capabilities extend beyond credential theft to encompass a wide range of sensitive data exfiltration. It intercepts SMS messages, crucial for capturing one-time passwords (OTPs) from banks, blocks incoming calls from financial institutions, and silently manipulates clipboard content to redirect cryptocurrency wallet addresses. This allows attackers to reroute financial transactions without the user ever detecting the alteration.
The malware communicates with its command and control (C2) servers via HTTPS, enabling it to blend in with normal network traffic. Upon initial contact, it transmits a comprehensive device profile, including hardware specifications, battery status, and storage information, to generate a unique bot ID. The sophisticated C2 infrastructure also incorporates multiple fallback domains, allowing the malware to dynamically switch between them if a primary domain is blocked or taken down.
What You Should Do
- Avoid Third-Party App Stores: Only download applications from the official Google Play Store. Unofficial sources are frequently used to distribute malware.
- Exercise Caution with Permissions: Be extremely wary of applications requesting Accessibility Service permissions, especially if they are not legitimate accessibility tools. Review all requested permissions carefully before granting them.
- Keep Software Updated: Ensure your Android operating system and all applications are regularly updated to benefit from the latest security patches.
- Utilize Mobile Threat Defense (MTD): Consider installing a reputable mobile threat defense solution to provide an additional layer of security against sophisticated malware like Rokarolla.
- Be Skeptical of Phishing: Remain vigilant against phishing attempts via email or SMS that prompt you to download applications from unfamiliar websites.
Indicators of Compromise (IoCs):-
The following IoCs were identified in the Zimperium zLabs research report.
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[://]infocontablidades[.]it[.]com/ |
Primary malware distribution site masquerading as TikTok or Google Chrome |
| Domain | beralisvc[.]info |
C2 fallback domain used for malware communication |
| Domain | blestorians[.]cfd |
C2 fallback domain used for malware communication |
| Domain | abiorime[.]cfd |
C2 fallback domain used for malware communication |
| Domain | morevoms[.]cfd |
C2 fallback domain used for malware communication |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.