<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sms-Interception on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/sms-interception/</link><description>Recent content in Sms-Interception on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 13:10:17 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/sms-interception/index.xml" rel="self" type="application/rss+xml"/><item><title>Rokarolla Android Trojan Steals PINs &amp; Crypto Funds</title><link>https://zxcloudsecurity.co.uk/posts/rokarolla-android-banking-trojan-pin-sms-crypto-theft/</link><pubDate>Tue, 16 Jun 2026 13:10:17 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/rokarolla-android-banking-trojan-pin-sms-crypto-theft/</guid><description>Rokarolla Android malware targets 217 banking and crypto apps, stealing PINs, intercepting SMS MFA codes, and hijacking crypto payments via clipboard rewri</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html">The Hacker News</a></p>
<hr>
<p>A newly documented Android banking trojan called Rokarolla targets 217 banking and cryptocurrency applications, giving attackers near-complete control of infected devices. It can steal lock-screen PINs, intercept SMS-based two-factor authentication codes, and hijack cryptocurrency transactions by silently rewriting clipboard content. With 137 remote commands at an operator&rsquo;s disposal, the potential for account takeover and financial theft is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Enforce mobile device management (MDM) policies that restrict sideloading and require app allowlisting on any corporate or BYOD devices accessing cloud workloads or financial systems. Additionally, review whether SMS-based MFA is used to protect privileged accounts and migrate to hardware tokens or authenticator apps, as SMS interception renders that second factor useless against this threat.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/new-rokarolla-android-malware-steals.html">New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds</a></p>
]]></content:encoded></item></channel></rss>