Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Abuse & Phishing

Rokarolla malware hijacks 217 banking, crypto apps

A new Android trojan uses 137 commands to steal credentials and financial data from targeted apps.

Rokarolla malware hijacks 217 banking, crypto apps
Denny Müller · Unsplash

Security researchers have uncovered a sophisticated Android malware campaign distributing a trojan named Rokarolla. The malware is designed to extract financial data from users by targeting over two hundred banking and cryptocurrency applications through deceptive overlays and extensive device control capabilities.

The Rokarolla trojan spreads via malicious websites that mimic legitimate app downloads, specifically posing as Google Chrome or TikTok installers. Once installed, the malware disguises itself as Google Play Protect, Android’s built-in security feature, to gain user trust during the setup process. This social engineering tactic is critical for obtaining the permissions necessary to execute its payload.

How the malware operates

Rokarolla begins its attack by requesting Accessibility service permissions, along with access to notifications, SMS, and call logs. These permissions allow the malware to interact with the device’s user interface, monitor user activity, and bypass standard security protections. Upon installation, it sends a detailed device profile to its command-and-control (C2) server, including hardware specifications, Android version, and system settings. This data is used to generate a unique identifier for each infected device, enabling targeted attacks.

The trojan checks the infected device against a predefined list of 217 financial applications, including banking and cryptocurrency platforms. When a targeted app is launched, Rokarolla deploys a fake login overlay to capture credentials, credit card details, and other sensitive information. These overlays are also used to steal lock-screen PINs or patterns, effectively granting the malware persistent access to the device even when locked. Additionally, the malware employs evasion techniques such as disabling Google Play Protect, hiding its app icon, and suppressing audio or vibration alerts to avoid detection.

Key facts
  • Rokarolla targets 217 banking and cryptocurrency apps with fake login overlays.
  • The malware uses 137 commands, including keylogging, SMS theft, and clipboard manipulation.
  • Distribution occurs via malicious websites impersonating Chrome or TikTok installers.
  • Rokarolla disables Google Play Protect and hides its icon to evade detection.
  • Zimperium researchers confirmed the malware is not present on Google Play.

Impact on users and businesses

Rokarolla’s capabilities extend beyond credential theft. The malware can record keystrokes, capture screenshots, and manipulate clipboard contents, providing attackers with near-complete control over the infected device. It can also block incoming calls and fraud alerts, further complicating efforts to mitigate financial losses. The combination of these features makes Rokarolla a potent tool for advanced financial fraud, particularly against users who rely on mobile banking or cryptocurrency applications.

For businesses, the emergence of Rokarolla underscores the growing sophistication of mobile malware targeting financial services. The trojan’s ability to bypass security measures like Google Play Protect highlights the limitations of relying solely on built-in Android protections. Organizations that support mobile banking or cryptocurrency transactions should prioritize user education on the risks of sideloading apps and the dangers of granting excessive permissions, particularly for Accessibility services.

For professionals

For professionals: Security teams should update detection rules to monitor for unusual Accessibility service usage or C2 communication patterns associated with Rokarolla. Endpoint protection solutions should be configured to flag apps requesting high-risk permissions, especially those distributed outside official app stores. Financial institutions may need to enhance fraud detection systems to account for the trojan’s ability to intercept SMS-based authentication codes.

Mitigation and recommendations

Zimperium, the mobile security firm that analyzed Rokarolla, confirmed the malware has not been found on Google Play. However, its distribution via third-party websites poses a significant risk to users who download APK files from untrusted sources. To reduce exposure, users should avoid sideloading apps unless they explicitly trust the publisher and verify the authenticity of download sources. Additionally, caution should be exercised when granting Accessibility permissions, as these can be exploited to bypass security controls and automate malicious actions.

Security teams are advised to review Zimperium’s GitHub repository, which documents all 137 commands used by Rokarolla. This resource can aid in developing detection signatures and understanding the malware’s full range of capabilities. Regular security awareness training for employees and customers can also help mitigate the risk of infection, particularly in organizations where mobile devices are used for financial transactions.

Discussion · coming soon

Be the first to join the thread when community discussion launches.