Affected Systems
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
Exploitation Status
Active campaign in the wild. Rokarolla is a newly discovered banking trojan actively targeting mobile banking and cryptocurrency users. Distribution method and infection vector not specified in available data.
Business Impact
Organizations with BYOD policies or corporate-issued Android devices face credential theft, financial fraud, and potential corporate account compromise. Extensive command set (137 commands) suggests advanced capabilities including keylogging, screen capture, SMS interception, and overlay attacks. No CVE assigned as this is malware campaign rather than software vulnerability. Financial services and cryptocurrency sectors at elevated risk.
Urgency
🟠Within 24 hours
Recommended Actions
- Deploy mobile threat defense (MTD) solutions on corporate Android devices to detect Rokarolla indicators
- Block sideloading of apps from unknown sources via MDM policy; enforce Google Play Protect on all managed devices
- Alert users to avoid installing apps from third-party stores and suspicious APK files distributed via phishing or messaging apps
- Monitor for anomalous Android device behavior: unexpected permission requests, overlay screens on banking apps, or unusual SMS/call activity
- Review and restrict Accessibility Service permissions on corporate devices; Rokarolla likely abuses these for overlay attacks and data theft
