New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps

2026-06-17T14:51:47Z1420199bfd6801364b9bf1a5a4ec2eb965f8b8ba15139e7887c00ac3010a46ec
APTCisco-Catalyst-SD-WAN','CVE-2026-20262'FishMongerFortiSandboxFortinetFulcrumSecNovo-NordiskSprySOCKSUEFIandroidbanking-trojancredential-theftdata-breachdata-theftedtechextortionhealthcare-breachiRhythmkernel-drivermalwareplay-protectprint-spoolerrokarollasms-interceptionvulnerability-exploitation

What happened

Feed of security news (June 16–17, 2026): Zimperium zLabs disclosed Rokarolla, a new Android banking trojan that targets 217 banking and crypto apps, steals credentials, intercepts SMS, blocks bank calls and disables Play Protect; EdTech sector sees rising data breaches with actors like ShinyHunters and FulcrumSec; FulcrumSec leaked ~1.3 TB from Novo Nordisk after a $25M extortion demand; ESET uncovered China-linked FishMonger variants of SprySOCKS for Windows using kernel drivers and Print Spooler with UEFI bootkit hints; iRhythm reported a cyberattack with patient/proprietary data theft and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1420199bfd6801364b9bf1a5a4ec2eb965f8b8ba15139e7887c00ac3010a46ec
Enrichment time
2026-06-17T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.