Skip to main content
Mallory
Malware

Rokarolla

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

17 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

The attack chain begins when a user visits a malicious website like infocontablidades.it.com . These pages actually contain the malware, hidden inside files that look like popular programs such as TikTok or Google Chrome.

T1566PhishingEvidence1

When a victim opens an authentic financial application, it queries the server’s endpoint to fetch fake HTML-based phishing pages. It then displays these fake login screens right on top of the legitimate apps.

Execution

1 technique
T1204.002Malicious FileEvidence1

Rokarolla ... spreads through malicious websites posing as well-known apps such as TikTok and Chrome. The first thing a victim installs is a dropper that pretends to be Google Play Protect.

Persistence

2 techniques
T1546Event Triggered ExecutionEvidence1

It uses that disguise to get the payload installed and grab Accessibility access. ... the playbook is the same one running through a wave of 2026 Android bankers: fake-app droppers, Accessibility abuse, and HTML overlays.

T1546.008Accessibility FeaturesEvidence1

Once installed, the malware asks for permission to use Android Accessibility Services. Then, it takes over these services to monitor the phone screen and track coordinates without user intervention.

Privilege Escalation

2 techniques
T1546Event Triggered ExecutionEvidence1

It uses that disguise to get the payload installed and grab Accessibility access. ... the playbook is the same one running through a wave of 2026 Android bankers: fake-app droppers, Accessibility abuse, and HTML overlays.

T1546.008Accessibility FeaturesEvidence1

Once installed, the malware asks for permission to use Android Accessibility Services. Then, it takes over these services to monitor the phone screen and track coordinates without user intervention.

Stealth

1 technique
T1036MasqueradingEvidence1

These pages actually contain the malware, hidden inside files that look like popular programs such as TikTok or Google Chrome. When a victim downloads this file, a secondary dropper runs first, disguised as a Google Play Protect security tool.

Credential Access

4 techniques
T1056Input CaptureEvidence1

The theft runs through overlays. Rokarolla pulls a target list from its server, and for each app flagged active, it downloads a fake HTML login page ... When the victim opens the real banking or wallet app, the malware drops the fake page on top and captures everything typed into it, card details included.

T1056.001KeyloggingEvidence2

A keylogger and screen logger record what the user types and sees...

T1111Multi-Factor Authentication InterceptionEvidence1

It reads every SMS on the device and can send messages itself, which is enough to grab the SMS one-time codes banks use to approve logins and transactions.

T1555Credentials from Password StoresEvidence1

A separate overlay mimics the Android lock screen to capture the PIN, pattern, or password, which lets the operator control the phone even while it is locked.

Collection

4 techniques
T1056Input CaptureEvidence1

The theft runs through overlays. Rokarolla pulls a target list from its server, and for each app flagged active, it downloads a fake HTML login page ... When the victim opens the real banking or wallet app, the malware drops the fake page on top and captures everything typed into it, card details included.

T1056.001KeyloggingEvidence2

A keylogger and screen logger record what the user types and sees...

T1113Screen CaptureEvidence2

For surveillance, Rokarolla skips the usual MediaProjection screen casting ... and instead takes screenshots through Accessibility, compresses them to PNG, and ships them out one frame at a time.

T1115Clipboard DataEvidence2

The clipboard gets rewritten silently, swapping in attacker wallet addresses so a copied crypto payment lands in the wrong account.

Command and Control

3 techniques
T1071Application Layer ProtocolEvidence1

This highly invasive malware is named after its command-and-control infrastructure... Researchers noted that the malware has 137 commands available to control the phone

T1071.001Web ProtocolsEvidence1

Rokarolla pulls a target list from its server ... it downloads a fake HTML login page ... The malware carries multiple fallback C2 domains and can be handed new ones on the fly...

T1568Dynamic ResolutionEvidence1

The malware carries multiple fallback C2 domains and can be handed new ones on the fly, so pulling a single server does little.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

...takes screenshots through Accessibility, compresses them to PNG, and ships them out one frame at a time.

Other

1 technique
T1562Impair DefensesEvidence2

Once the malware is running, one of its commands turns Play Protect off.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping17

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.