
Rokarolla deploys 137 remote commands and HTML overlays to drain 217 banking and crypto apps via Accessibility abuse
Rokarolla extends the 2026 Android banker wave by hardening Accessibility abuse and overlay delivery against Play Protect. Evidence from Zimperium samples shows no state attribution but clear intent to bypass lock screens and SMS verification. Defenses stay limited to installation hygiene and detection rules already published.
Zimperium zLabs documented the family through samples that fetch target lists from C2 servers named after the Rokarolla domain set. The dropper requests Accessibility Service access, then disables Play Protect while storing HTML overlays locally for immediate use against active banking sessions. This matches the 2025-2026 pattern seen in HOOK and Klopatra families where Accessibility replaces riskier screen-casting methods.
Procurement records and GitHub IOC releases show operators rotate fallback domains faster than takedown cycles allow. The 137 commands exceed HOOK's 107, adding lock-screen overlays and silent screenshot exfiltration that avoid MediaProjection prompts. No independent technical attribution ties the build to a named group; Zimperium explicitly declined to link it to prior campaigns.
The operational shift toward fake-app distribution via malicious websites rather than sideloading stores indicates maturing supply chains for Android credential theft. Banks relying on SMS 2FA and users who grant Accessibility for utilities face direct fund redirection without visible alerts. Standard Play Store-only installs remain the only scalable control.
Next indicators to monitor include new C2 domains matching the Rokarolla naming convention and reports of clipboard swaps hitting major wallet apps within 90 days.
Zimperium: At least three new Rokarolla C2 domains will appear in public IOC feeds before October 2026 with matching command counts above 130.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html)
- [2]Supporting Source(https://www.zimperium.com/blog/rokarolla-analysis)
- [3]Supporting Source(https://securelist.com/hook-trojan-comparison-2025)