Rokarolla
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
1 technique
Execution
Persistence
2 techniques
Persistence
Privilege Escalation
2 techniques
Privilege Escalation
Stealth
1 technique
Stealth
Credential Access
4 techniques
Credential Access
The theft runs through overlays. Rokarolla pulls a target list from its server, and for each app flagged active, it downloads a fake HTML login page ... When the victim opens the real banking or wallet app, the malware drops the fake page on top and captures everything typed into it, card details included.
Collection
4 techniques
Collection
The theft runs through overlays. Rokarolla pulls a target list from its server, and for each app flagged active, it downloads a fake HTML login page ... When the victim opens the real banking or wallet app, the malware drops the fake page on top and captures everything typed into it, card details included.
Command and Control
3 techniques
Command and Control
This highly invasive malware is named after its command-and-control infrastructure... Researchers noted that the malware has 137 commands available to control the phone
Exfiltration
1 technique
Exfiltration
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan spread via malicious websites impersonating popular apps. It uses a fake Google Play Protect dropper to install the payload and obtain Accessibility access, disables Play Protect, deploys HTML overlay phishing pages against banking and crypto apps, steals lock-screen credentials, reads and sends SMS, captures one-time codes, logs keystrokes and screens, scrapes contacts and notifications, rewrites clipboard crypto addresses, blocks calls, and exfiltrates screenshots via Accessibility-based capture.
Android banking trojan that uses malicious websites and a secondary dropper to install on devices, abuses Accessibility Services, intercepts SMS and calls, deploys fake overlays over legitimate financial apps to steal credentials, performs keylogging, screenshots, clipboard hijacking, and uses a Pseudo-VNC-style screen monitoring capability for full device surveillance and control.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.