{"id":606,"date":"2026-06-19T15:24:14","date_gmt":"2026-06-19T09:54:14","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=606"},"modified":"2026-08-18T15:27:25","modified_gmt":"2026-08-18T09:57:25","slug":"rokarolla-android-trojan-combines-banking-overlays-with-full-device-control","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/","title":{"rendered":"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control"},"content":{"rendered":"<p>Android banking malware continues to evolve beyond simple credential theft. The latest example is Rokarolla Android malware, a newly discovered banking trojan that combines phishing overlays, keylogging, accessibility abuse, and remote device control capabilities. Security researchers have identified Rokarolla targeting 217 banking and cryptocurrency applications, giving attackers the ability to steal sensitive information and manipulate infected devices remotely.<\/p>\n<p>Unlike traditional banking trojans that focus solely on financial fraud, Rokarolla turns infected Android devices into highly controlled attack platforms. By abusing Android Accessibility Services and acquiring extensive permissions, the malware can capture credentials, intercept communications, bypass security prompts, and maintain control even when the device is locked.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tSecure Android devices with Hexnode UEM <\/a>\r\n    \t\t<\/center><\/p>\n<h2>How Rokarolla Android Malware Infects Devices<\/h2>\n<p>Researchers report that Rokarolla primarily spreads through malicious websites masquerading as trusted download sources for popular applications such as Google Chrome and TikTok.<\/p>\n<p>Victims who visit these websites are prompted to download what appears to be a legitimate application. However, the downloaded package acts as a malware dropper. During installation, the malware imitates Google Play Protect, creating a false sense of security while guiding users through a fake application installation process.<\/p>\n<p>Once installed, Rokarolla requests several high-risk permissions, including:<\/p>\n<ul>\n<li>Accessibility Services access<\/li>\n<li>SMS permissions<\/li>\n<li>Notification access<\/li>\n<li>Call management permissions<\/li>\n<\/ul>\n<p>These permissions provide attackers with extensive visibility into user activity and device operations.<\/p>\n<p>Before launching its primary attack routines, the malware profiles the infected device by collecting information such as:<\/p>\n<table>\n<thead>\n<tr>\n<th>Device Information Collected<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Device model<\/td>\n<td>Victim profiling<\/td>\n<\/tr>\n<tr>\n<td>Android version<\/td>\n<td>Compatibility checks<\/td>\n<\/tr>\n<tr>\n<td>Locale settings<\/td>\n<td>Regional targeting<\/td>\n<\/tr>\n<tr>\n<td>Screen characteristics<\/td>\n<td>Overlay customization<\/td>\n<\/tr>\n<tr>\n<td>Battery status<\/td>\n<td>Operational monitoring<\/td>\n<\/tr>\n<tr>\n<td>Storage information<\/td>\n<td>Resource assessment<\/td>\n<\/tr>\n<tr>\n<td>RAM details<\/td>\n<td>Performance optimization<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This profiling helps attackers tailor malicious actions to individual devices.<\/p>\n<h2>Why Rokarolla Is a Serious BYOD Security Threat<\/h2>\n<p>The rise of hybrid work has increased organizational dependence on smartphones and tablets. Many employees access business applications, corporate email, collaboration platforms, and identity systems from personal devices.<\/p>\n<p>This makes <a href=\"https:\/\/www.hexnode.com\/blogs\/a-quick-guide-to-byod-management-on-android-and-ios\/\">BYOD security<\/a> a critical concern.<\/p>\n<p>When a device infected with Rokarolla accesses enterprise resources, attackers may gain indirect access to business data and workflows. Even if the malware primarily targets financial applications, its broader surveillance capabilities create additional enterprise risks.<\/p>\n<p>Potential consequences include:<\/p>\n<ul>\n<li>Interception of multifactor authentication codes<\/li>\n<li>Theft of corporate email sessions<\/li>\n<li>Exposure of sensitive business communications<\/li>\n<li>Credential harvesting from SaaS applications<\/li>\n<li>Monitoring of employee activity<\/li>\n<li>Unauthorized access to business accounts<\/li>\n<\/ul>\n<p>Accessibility abuse is particularly concerning because it allows attackers to interact with user interfaces in ways that appear legitimate. Malware can potentially approve prompts, interact with applications, and bypass assumptions about user intent.<\/p>\n<p>For organizations supporting BYOD environments, mobile malware infections can quickly become identity and access management incidents.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Infographics_Steps-to-create-an-effective-BYOD-policy.webp?format=webp\" class=\"resource-box__image\" alt=\"Infographics_Steps-to-create-an-effective-BYOD-policy\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Infographics_Steps-to-create-an-effective-BYOD-policy.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Infographics_Steps-to-create-an-effective-BYOD-policy-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Infographics_Steps-to-create-an-effective-BYOD-policy-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Infographics_Steps-to-create-an-effective-BYOD-policy-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Infographics_Steps-to-create-an-effective-BYOD-policy\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Steps to create an effective BYOD policy\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn the key steps to build a secure, effective BYOD policy for your organization.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/steps-to-create-an-effective-byod-policy\/'>\n                            Download the Infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode Helps Defend Against Android Banking Malware<\/h2>\n<p>Organizations need proactive controls to reduce the risk posed by sophisticated Android threats such as Rokarolla.<\/p>\n<h3>Enforce Secure Android Device Compliance with Hexnode UEM<\/h3>\n<p>Hexnode <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-unified-endpoint-management-uem\/\">UEM<\/a> lets administrators define Android compliance policies, and when integrated with an IdP such as Microsoft Entra ID or Okta, device compliance status can support conditional access decisions.<\/p>\n<p>Administrators can:<\/p>\n<ul>\n<li>Restrict installation of unauthorized applications<\/li>\n<li>Enforce managed application deployment<\/li>\n<li>Monitor device compliance status<\/li>\n<li>Identify devices running risky configurations<\/li>\n<li>Apply Android security policies across corporate and BYOD devices<\/li>\n<\/ul>\n<p>By reducing opportunities for users to install untrusted applications, organizations can significantly lower the likelihood of malware infections originating from unofficial download sources.<\/p>\n<p>Hexnode UEM enables administrators to define device compliance controls and share compliance status with supported IdP Conditional Access workflows.<\/p>\n<h3>Accelerate Threat Detection with Hexnode XDR<\/h3>\n<p>While preventive controls remain essential, organizations also need visibility into suspicious activity that may indicate compromise.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> unifies endpoint telemetry, automated alert correlation, and remediation in a single dashboard, with alerts enriched by device health information, owner profiles, and active UEM policy configurations.<\/p>\n<p>Security teams can investigate:<\/p>\n<ul>\n<li>Suspicious authentication behavior<\/li>\n<li>Abnormal endpoint activity<\/li>\n<li>Potential compromise patterns across environments<\/li>\n<\/ul>\n<p>Correlating mobile risk signals with broader security telemetry helps organizations identify and contain threats before attackers achieve their objectives.<\/p>\n<p>As mobile malware continues to gain advanced capabilities, unified visibility becomes increasingly important for incident response and threat hunting operations.<\/p>\n<h2>Conclusion<\/h2>\n<p>The discovery of Rokarolla Android malware highlights how modern mobile threats are evolving beyond traditional banking fraud. By combining phishing overlays, accessibility abuse, credential theft, keylogging, and extensive remote-control functionality, Rokarolla gives attackers near-complete control over infected Android devices.<\/p>\n<p>For organizations supporting Android deployments and BYOD programs, the threat extends beyond financial loss. Compromised devices can expose identities, corporate communications, SaaS applications, and business workflows.<\/p>\n<p>Defending against these threats requires a combination of device compliance enforcement, application control, risky-permission monitoring, and rapid response capabilities. Organizations that implement strong mobile security controls will be better positioned to detect and contain the next generation of Android banking trojans before they can cause significant damage.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Defend Android Devices From Malware<\/h5><p>Secure BYOD endpoints with Hexnode UEM and XDR to detect threats and enforce compliance faster.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How do Android Accessibility Services become a security risk?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Accessibility Services are designed to help users interact with devices more effectively. However, malicious applications can abuse these permissions to observe screen activity, perform actions on behalf of users, capture input, and interact with applications without requiring direct user interaction.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can enterprise mobile security controls reduce the impact of phishing overlays?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Organizations can reduce exposure by enforcing trusted app sources, restricting application installation, monitoring device compliance, requiring secure authentication methods, and limiting access from devices that fail security policy requirements.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Android banking malware continues to evolve beyond simple credential theft. The latest example is Rokarolla&#8230;<\/p>\n","protected":false},"author":6,"featured_media":609,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,18],"class_list":["post-606","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-mobile","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Android Banking Trojan Rokarolla Targets 217 Apps<\/title>\n<meta name=\"description\" content=\"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Android Banking Trojan Rokarolla Targets 217 Apps\" \/>\n<meta property=\"og:description\" content=\"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-19T09:54:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:57:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control\",\"datePublished\":\"2026-06-19T09:54:14+00:00\",\"dateModified\":\"2026-08-18T09:57:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/\"},\"wordCount\":939,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp\",\"articleSection\":[\"Malware\",\"Mobile\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/\",\"name\":\"Android Banking Trojan Rokarolla Targets 217 Apps\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp\",\"datePublished\":\"2026-06-19T09:54:14+00:00\",\"dateModified\":\"2026-08-18T09:57:25+00:00\",\"description\":\"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Android Banking Trojan Rokarolla Targets 217 Apps","description":"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/","og_locale":"en_US","og_type":"article","og_title":"Android Banking Trojan Rokarolla Targets 217 Apps","og_description":"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-19T09:54:14+00:00","article_modified_time":"2026-08-18T09:57:25+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control","datePublished":"2026-06-19T09:54:14+00:00","dateModified":"2026-08-18T09:57:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/"},"wordCount":939,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp","articleSection":["Malware","Mobile"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/","url":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/","name":"Android Banking Trojan Rokarolla Targets 217 Apps","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp","datePublished":"2026-06-19T09:54:14+00:00","dateModified":"2026-08-18T09:57:25+00:00","description":"Android banking trojan Rokarolla targets banking and crypto apps with phishing overlays and accessibility abuse creating BYOD security risks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Rokarolla-Android-Trojan-Combines-Banking-Overlays-With-Full-Device-Control.png?format=webp","width":1340,"height":700,"caption":"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/rokarolla-android-trojan-combines-banking-overlays-with-full-device-control\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Rokarolla Android Trojan Combines Banking Overlays With Full Device Control"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=606"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/606\/revisions"}],"predecessor-version":[{"id":612,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/606\/revisions\/612"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/609"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}