Zimperium: Android banking trojan attacks 217 financial apps, stealing user credentials
According to Zimperium, the Android Trojan Rokarolla spreads through 217 banking and crypto applications, disguising itself as malicious websites like TikTok and Chrome, stealing unlock credentials and intercepting input; after infection, it steals credentials when opening financial apps and displays fake login pages. The malware contains 137 commands, capable of controlling the device, collecting SMS messages, stealing contacts, recording input, monitoring the screen, and even blocking calls, muting, disabling Play Protect, covering over 200 financial and social media apps, aiming for financial fraud and preventing victims from interrupting.