Zimperium's zLabs has documented Rokarolla, a new Android banking trojan targeting 217 banking and cryptocurrency apps with 137 remote commands. It spreads via fake app droppers impersonating TikTok and Chrome, then abuses Android Accessibility permissions to disable Google Play Protect, overlay fake login pages on banking apps, steal PINs via a fake lock screen, intercept SMS one-time codes, rewrite clipboard addresses to hijack crypto payments, and take covert screenshots. The malware maintains multiple fallback C2 domains, making server takedowns ineffective. No patch exists since it's malware rather than a product vulnerability; defenses include installing apps only from Google Play, keeping Play Protect enabled, and rejecting unexpected Accessibility permission requests. Indicators of compromise are published on Zimperium's GitHub.

3m read timeFrom thenextweb.com
Post cover image
85 Impressions