Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking and Crypto Apps — Threadlinqs Intelligence
As of 2026-07-11, Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking and Crypto Apps is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1225 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Rokarolla is an Android banking trojan distributed via fake app-download sites impersonating TikTok, Google Chrome, and Google Play Protect. It abuses Accessibility Services to run HTML phishing
Rokarolla is a newly documented Android banking trojan first analyzed by Zimperium zLabs (published 2026-06-16) and independently reported by PolySwarm, with subsequent coverage from Cyber Security News, BleepingComputer, The Hacker News, Help Net Security, Malwarebytes, GBHackers, and Infosecurity Magazine (late June 2026). The malware is distributed through malicious websites carefully designed to impersonate legitimate software download portals for TikTok, Google Chrome, and Google Play Protect. Victims who visit these sites are lured into sideloading a dropper APK that masquerades as Google Play Protect; the dropper then installs a second-stage payload while requesting SMS access, the default SMS-handler role, call-handler role, notification-listener access, and Android Accessibility Service permissions.
Once Accessibility Service access is granted, Rokarolla gains near-total control of the device without needing further user interaction. It parses on-screen UI nodes and coordinates to identify which app is in the foreground, and when the victim opens one of at least 217 targeted banking or cryptocurrency applications, the malware downloads and renders an HTML-based phishing overlay tailored to that specific app (researchers observed a fake overlay mimicking the Spanish 'imagin' banking app, a CaixaBank digital-banking brand). These overlays are rendered nearly identical to the legitimate login screens and are used to harvest usernames, passwords, PINs, patterns, and payment-card data, including fraudulent Android lock-screen overlays used to capture device unlock credentials directly.
Beyond overlay phishing, Rokarolla intercepts and can send SMS messages in real time, allowing it to steal one-time passcodes used for two-factor authentication and transaction approval before the victim ever sees them. It abuses Accessibility Services for silent keylogging and on-screen text extraction (including harvesting WhatsApp contacts), monitors and swaps clipboard content to redirect cryptocurrency transfers to attacker-controlled wallet addresses, and can block or intercept incoming phone calls to suppress bank fraud-warning calls. For visual surveillance, rather than using the conventional Android MediaProjection screen-recording API (which would trigger a visible recording indicator), Rokarolla implements a snapshot-based mechanism: it periodically captures the screen via Accessibility, compresses frames to PNG, and exfiltrates them one at a time to the C2 server, resetting state and cleaning up after each transmission.
For persistence and evasion, Rokarolla attempts to disable Google Play Protect, hides its app icon after installation, suppresses notifications and vibration, and keeps the display forced on to prevent screen-timeout interruptions to its background operations. On first contact with its command-and-control infrastructure over HTTPS, the malware transmits a device fingerprint/telemetry profile (phone model, Android version, locale, display characteristics, battery level, storage capacity, and available RAM) to generate a unique bot ID, then queries the C2 for the current list of 217 targeted banking/cryptocurrency apps along with corresponding phishing overlay resources and injection status values. The malware exposes at least 137 distinct operator commands spanning surveillance, credential exfiltration, SMS/call manipulation, clipboard hijacking, and device management, and supports multiple fallback C2 domains with dynamically-updatable configuration for resilience against takedown. Observed C2 domains include beralisvc.info, blestorians.cfd, abiorime.cfd, and morevoms.cfd; a fake distribution site impersonating TikTok/Chrome was identified at infocontablidades.it.com. No CVE applies (this is malware distribution/behavior, not a software vulnerability), and no specific threat-actor group name or nation-state attribution has been published; the financially-motivated targeting of banking and crypto credentials is
Weaknesses (CWE)
CWE-451, CWE-287, CWE-311
Target sectors: financial services, banking, cryptocurrency
Target regions: Global, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1476, T1624, T1541, T1626, T1655, T1516, T1629.003, T1628.002, T1417