Rokarolla Android banking trojan targets 217 banking and cryptocurrency apps through fake Chrome and TikTok downloads

A newly reported Android malware strain called Rokarolla is stealing financial data from people who install fake Chrome or TikTok apps from malicious websites. Zimperium says the trojan abuses Android Accessibility permissions, notifications, SMS, and call access, then checks for 217 targeted banking and crypto apps and downloads matching fake login overlays to capture credentials, card data, lock-screen PINs, contacts, SMS, and other device data. The malware also uses 137 command-and-control instructions and can disable Google Play Protect and hide its icon.
Why it matters: This can let criminals take over phones and drain financial accounts, especially when victims sideload apps outside Google Play. Android users should avoid APKs from unofficial sites, review Accessibility requests carefully, and treat unexpected prompts to install Chrome, TikTok, or security updates as suspicious.

Sources

Rokarolla Banking Trojan Targets 200 Applications
Eduard Kovacs 2026.06.18 98% relevant
This article is a direct report on the same Rokarolla Android malware campaign, adding details on distribution via fake Chrome and TikTok apps, lockscreen credential theft, WhatsApp contact harvesting, SMS and call hijacking, screenshot exfiltration, keylogging, clipboard hijacking, and Google Play Protect evasion.
New Rokarolla Android malware targets 217 banking, crypto apps
Bill Toulas 2026.06.16 100% relevant
This article appears to be the first concrete report in the dataset establishing Rokarolla as a distinct Android banking-malware campaign, with named malware, delivery method, targeting scope, and technical capabilities.
← Back to all stories