
New Android Threat Steals Banking Information and Cryptocurrency
A dangerous new Android malware called Rokarolla targets banking and crypto apps, stealing PINs and text messages to drain accounts.
Source
The Hacker News
Original headline: New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Plain-English summary by GetCyberRight. Read the full report at the source above.
Security researchers at Zimperium discovered a new type of malicious software targeting Android phones. This malware, called Rokarolla, specifically attacks 217 different banking and cryptocurrency apps. Once installed on a phone, it can steal lock screen PINs, read and send text messages, and redirect cryptocurrency payments by changing information you copy and paste.
If you use an Android phone and have banking apps or cryptocurrency wallets installed, you could be at risk. Rokarolla gives criminals nearly complete control over an infected device. It can turn off Google Play Protect, which normally helps defend your phone. The malware steals the security codes sent via text message, allowing thieves to break into your accounts even if you have two factor authentication enabled.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Take these steps immediately to protect yourself. First, only download apps from the official Google Play Store and check reviews carefully before installing anything. Second, go to Settings, then Security, and make sure Google Play Protect is turned on and scanning your device. Third, review all apps currently installed on your phone and delete any you do not recognize or no longer use. Fourth, enable biometric login like fingerprint or face recognition for your banking apps instead of relying only on PINs. Fifth, contact your bank immediately if you notice any suspicious transactions or if your phone starts behaving strangely. For long term protection, keep your Android system updated with the latest security patches. Avoid clicking links in unexpected text messages or emails, even if they appear to come from your bank. Consider using a separate, older device for banking if you frequently download new apps on your main phone. Monitor your bank and credit card statements weekly for unauthorized charges.
Curated from trusted cybersecurity sources by GetCyberRight
Source: The Hacker NewsStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Scammers Weaponize Telegram's Edit Button to Fake Exam Answer Keys
Fraudsters are exploiting Telegram's message editing feature to create convincing exam cheating scams. Here's how to protect students in your family.
4 min readUK Social Media Age Checks Will Require Your ID: What Parents Need to Know
New UK rules starting spring 2027 will require uploading government IDs or face scans for social media accounts, creating serious privacy risks for your family.
4 min readUK Social Media Age Checks Could Put Your Teen's Identity at Risk
New UK rules require teens to upload government IDs or facial scans to use social media. These databases create a major new target for identity thieves.
4 min read
Fake Error Messages Trick People Into Installing Harmful Software
Criminals are using hacked websites to show fake error messages that trick visitors into running commands that install malware on their computers.
2 min read