Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking and Crypto Apps
Rokarolla Android Banking Trojan Intercepts SMS OTPs and (TL-2026-1225), also tracked as Rokarolla, is a high-severity malware campaign, first published 2026-07-11. It has no confirmed attribution, affects Google Android, maps to 22 MITRE ATT&CK techniques (T1414, T1417, T1418), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1225
- Threat ID
- TL-2026-1225
- Also known as
- Rokarolla
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, cryptocurrency
- Target regions
- Global, Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Rokarolla Android Banking Trojan Intercepts SMS OTPs and
Malware and tooling: Rokarolla
Rokarolla is an Android banking trojan distributed via fake app-download sites impersonating TikTok, Google Chrome, and Google Play Protect. It abuses Accessibility Services to run HTML phishing overlays, intercept SMS OTPs, log keystrokes, capture screenshots, hijack clipboard crypto addresses, and block fraud-warning calls, targeting 217+ banking/crypto apps via 137 operator commands and multiple fallback C2 domains.
How Rokarolla Android Banking Trojan Intercepts SMS OTPs and works
Rokarolla is a newly documented Android banking trojan first analyzed by Zimperium zLabs (published 2026-06-16) and independently reported by PolySwarm, with subsequent coverage from Cyber Security News, BleepingComputer, The Hacker News, Help Net Security, Malwarebytes, GBHackers, and Infosecurity Magazine (late June 2026). The malware is distributed through malicious websites carefully designed to impersonate legitimate software download portals for TikTok, Google Chrome, and Google Play Protect. Victims who visit these sites are lured into sideloading a dropper APK that masquerades as Google Play Protect; the dropper then installs a second-stage payload while requesting SMS access, the default SMS-handler role, call-handler role, notification-listener access, and Android Accessibility Service permissions.
Once Accessibility Service access is granted, Rokarolla gains near-total control of the device without needing further user interaction. It parses on-screen UI nodes and coordinates to identify which app is in the foreground, and when the victim opens one of at least 217 targeted banking or cryptocurrency applications, the malware downloads and renders an HTML-based phishing overlay tailored to that specific app (researchers observed a fake overlay mimicking the Spanish 'imagin' banking app, a CaixaBank digital-banking brand). These overlays are rendered nearly identical to the legitimate login screens and are used to harvest usernames, passwords, PINs, patterns, and payment-card data, including fraudulent Android lock-screen overlays used to capture device unlock credentials directly.
Beyond overlay phishing, Rokarolla intercepts and can send SMS messages in real time, allowing it to steal one-time passcodes used for two-factor authentication and transaction approval before the victim ever sees them. It abuses Accessibility Services for silent keylogging and on-screen text extraction (including harvesting WhatsApp contacts), monitors and swaps clipboard content to redirect cryptocurrency transfers to attacker-controlled wallet addresses, and can block or intercept incoming phone calls to suppress bank fraud-warning calls. For visual surveillance, rather than using the conventional Android MediaProjection screen-recording API (which would trigger a visible recording indicator), Rokarolla implements a snapshot-based mechanism: it periodically captures the screen via Accessibility, compresses frames to PNG, and exfiltrates them one at a time to the C2 server, resetting state and cleaning up after each transmission.
For persistence and evasion, Rokarolla attempts to disable Google Play Protect, hides its app icon after installation, suppresses notifications and vibration, and keeps the display forced on to prevent screen-timeout interruptions to its background operations. On first contact with its command-and-control infrastructure over HTTPS, the malware transmits a device fingerprint/telemetry profile (phone model, Android version, locale, display characteristics, battery level, storage capacity, and available RAM) to generate a unique bot ID, then queries the C2 for the current list of 217 targeted banking/cryptocurrency apps along with corresponding phishing overlay resources and injection status values. The malware exposes at least 137 distinct operator commands spanning surveillance, credential exfiltration, SMS/call manipulation, clipboard hijacking, and device management, and supports multiple fallback C2 domains with dynamically-updatable configuration for resilience against takedown. Observed C2 domains include beralisvc.info, blestorians.cfd, abiorime.cfd, and morevoms.cfd; a fake distribution site impersonating TikTok/Chrome was identified at infocontablidades.it.com. No CVE applies (this is malware distribution/behavior, not a software vulnerability), and no specific threat-actor group name or nation-state attribution has been published; the financially-motivated targeting of banking and crypto credentials is consistent with a cybercriminal fraud operation rather than state-sponsored activity. Zimperium published a companion GitHub IOC repository containing sample APK hashes and the full list of 137 operator commands.
MITRE ATT&CK techniques used in TL-2026-1225
Collection
T1414 Clipboard Data; T1513 Screen Capture; T1616 Call Control; T1636 Protected User Data
collection
T1417 Input Capture; T1517 Access Notifications
Discovery
T1418 Software Discovery; T1426 System Information Discovery
initial-access
T1476 Deliver Malicious App via Other Means; T1660 Phishing
command-and-control
T1481 Web Service; T1637 Dynamic Resolution
defense-evasion
T1516 Input Injection; T1628.002 User Evasion; T1629.003 Disable or Modify Tools; T1655 Masquerading
Persistence
T1541 Foreground Persistence; T1624 Event Triggered Execution
Impact
T1582 SMS Control; T1642 Endpoint Denial of Service
privilege-escalation
T1626 Abuse Elevation Control Mechanism
Exfiltration
Affected products and versions in Rokarolla Android Banking Trojan Intercepts SMS OTPs and
- Google — Android
Vulnerable versions: All Android versions supporting Accessibility Services and sideloaded APK installation - Various — 217+ banking and cryptocurrency mobile applications (e.g., imagin/CaixaBank digital banking app)
Vulnerable versions: Any version running on a compromised Android device
Remediation for Rokarolla Android Banking Trojan Intercepts SMS OTPs and
Immediate actions
- Block/monitor identified C2 domains (beralisvc.info, blestorians.cfd, abiorime.cfd, morevoms.cfd) and distribution domain infocontablidades.it.com at DNS/proxy layer
- Audit installed apps for sideloaded APKs claiming to be TikTok, Google Chrome, or Google Play Protect that were not installed from Google Play
- Revoke Accessibility Service, SMS-handler, and call-handler permissions from any unrecognized or recently-sideloaded app
- Uninstall any app matching the published SHA-256 hash indicators
Workarounds
- Only install apps from the official Google Play Store
- Deny Accessibility Service access to any app that is not a legitimate accessibility tool
- Enable Google Play Protect and do not allow it to be disabled by third-party apps
Longer-term hardening
- Deploy Mobile Threat Defense (MTD) / on-device malware detection capable of flagging unauthorized Accessibility Service usage and sideloading behavior
- Enforce enterprise mobile policy blocking installation from unknown sources (disable sideloading) on managed devices
- Implement runtime application self-protection (RASP) in banking/crypto apps to detect overlay attacks and screen-reading via Accessibility Services
- User education on avoiding third-party app-download sites and scrutinizing Accessibility Service permission prompts
Weaknesses (CWE) in Rokarolla Android Banking Trojan Intercepts SMS OTPs and
CWE-451, CWE-287, CWE-311
Timeline of Rokarolla Android Banking Trojan Intercepts SMS OTPs and
- The Hacker News publishes 'New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds' summarizing the Zimperium report
- BleepingComputer publishes initial coverage of Zimperium's Rokarolla findings, confirming 217 targeted apps and 137 operator commands
- Zimperium zLabs publishes initial technical analysis 'Rokarolla: Android Banker with Complete Device Takeover Capabilities', including MITRE ATT&CK mapping and a companion IOC GitHub repository (2026-06-Rokarolla) containing apks.csv and commands.md
- Help Net Security, GBHackers, and Infosecurity Magazine publish follow-up analysis, highlighting the fake Google Play Protect dropper and the 'imagin' (CaixaBank) bank overlay example
- Malwarebytes Labs publishes consumer-facing analysis describing Rokarolla's fake Google Play Protect dropper and full-device-takeover capability
- BleepingComputer's original coverage is revised/updated (article carries an 18 June 2026 update note) following continued analysis of the Zimperium disclosure
- PolySwarm publishes independent analysis 'Beyond Banking Trojans: Rokarolla Expands the Android Fraud Playbook', cross-referencing 34 SHA-256 sample hashes via its threat-intelligence portal
- Cyber Security News republishes PolySwarm's findings, describing the malware as "one of the more complete mobile fraud platforms seen in the Android malware space so far this year"
- Threadlinqs Intelligence Platform ingests and researches the Rokarolla threat as TL-2026-1225
Sources cited for Rokarolla Android Banking Trojan Intercepts SMS OTPs and
- Hackers Use Rokarolla Banking Trojan to Intercept SMS Codes and Steal Crypto Credentials
- Beyond Banking Trojans: Rokarolla Expands the Android Fraud Playbook
- Rokarolla: Android Banker with Complete Device Takeover Capabilities
- New Rokarolla Android malware targets 217 banking, crypto apps
- New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
- Rokarolla Android trojan targets banking and crypto users, enables device takeover
- Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
- Rokarolla Trojan Combines Banking Fraud With Device Surveillance
- Rokarolla Android malware can take over your phone and steal banking logins
- Zimperium/IOC GitHub repository - 2026-06-Rokarolla
Threats related to Rokarolla Android Banking Trojan Intercepts SMS OTPs and
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users in France, Italy, and Austria
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
Detection coverage for TL-2026-1225
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1225 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1225
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.