New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps
2026-06-17T14:51:47Z•1420199bfd6801364b9bf1a5a4ec2eb965f8b8ba15139e7887c00ac3010a46ec
APTCisco-Catalyst-SD-WAN','CVE-2026-20262'FishMongerFortiSandboxFortinetFulcrumSecNovo-NordiskSprySOCKSUEFIandroidbanking-trojancredential-theftdata-breachdata-theftedtechextortionhealthcare-breachiRhythmkernel-drivermalwareplay-protectprint-spoolerrokarollasms-interceptionvulnerability-exploitation
What happened
Feed of security news (June 16–17, 2026): Zimperium zLabs disclosed Rokarolla, a new Android banking trojan that targets 217 banking and crypto apps, steals credentials, intercepts SMS, blocks bank calls and disables Play Protect; EdTech sector sees rising data breaches with actors like ShinyHunters and FulcrumSec; FulcrumSec leaked ~1.3 TB from Novo Nordisk after a $25M extortion demand; ESET uncovered China-linked FishMonger variants of SprySOCKS for Windows using kernel drivers and Print Spooler with UEFI bootkit hints; iRhythm reported a cyberattack with patient/proprietary data theft and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1420199bfd6801364b9bf1a5a4ec2eb965f8b8ba15139e7887c00ac3010a46ec
- Enrichment time
- 2026-06-17T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.