Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Abuse & Phishing Zimperium

Rokarolla malware hijacks 217 banking, crypto apps

A new Android trojan uses 137 commands to steal credentials and financial data from targeted apps.

Rokarolla malware hijacks 217 banking, crypto apps
Denny Müller · Unsplash

Security researchers have uncovered a sophisticated Android malware campaign distributing a trojan named Rokarolla. The malware is designed to extract financial data from users by targeting over two hundred banking and cryptocurrency applications through deceptive overlays and extensive device control capabilities.

The Rokarolla trojan spreads via malicious websites that mimic legitimate app downloads, specifically posing as Google Chrome or TikTok installers. Once installed, the malware disguises itself as Google Play Protect, Android’s built-in security feature, to gain user trust during the setup process. This social engineering tactic is critical for obtaining the permissions necessary to execute its payload.

How the malware operates

Rokarolla begins its attack by requesting Accessibility service permissions, along with access to notifications, SMS, and call logs. These permissions allow the malware to interact with the device’s user interface, monitor user activity, and bypass standard security protections. Upon installation, it sends a detailed device profile to its command-and-control (C2) server, including hardware specifications, Android version, and system settings. This data is used to generate a unique identifier for each infected device, enabling targeted attacks.

The trojan checks the infected device against a predefined list of 217 financial applications, including banking and cryptocurrency platforms. When a targeted app is launched, Rokarolla deploys a fake login overlay to capture credentials, credit card details, and other sensitive information. These overlays are also used to steal lock-screen PINs or patterns, effectively granting the malware persistent access to the device even when locked. Additionally, the malware employs evasion techniques such as disabling Google Play Protect, hiding its app icon, and suppressing audio or vibration alerts to avoid detection.

Key facts
  • Rokarolla targets 217 banking and cryptocurrency apps with fake login overlays.
  • The malware uses 137 commands, including keylogging, SMS theft, and clipboard manipulation.
  • Distribution occurs via malicious websites impersonating Chrome or TikTok installers.
  • Rokarolla disables Google Play Protect and hides its icon to evade detection.
  • Zimperium researchers confirmed the malware is not present on Google Play.

Impact on users and businesses

Rokarolla’s capabilities extend beyond credential theft. The malware can record keystrokes, capture screenshots, and manipulate clipboard contents, providing attackers with near-complete control over the infected device. It can also block incoming calls and fraud alerts, further complicating efforts to mitigate financial losses. The combination of these features makes Rokarolla a potent tool for advanced financial fraud, particularly against users who rely on mobile banking or cryptocurrency applications.

For businesses, the emergence of Rokarolla underscores the growing sophistication of mobile malware targeting financial services. The trojan’s ability to bypass security measures like Google Play Protect highlights the limitations of relying solely on built-in Android protections. Organizations that support mobile banking or cryptocurrency transactions should prioritize user education on the risks of sideloading apps and the dangers of granting excessive permissions, particularly for Accessibility services.

For professionals

For professionals: Security teams should update detection rules to monitor for unusual Accessibility service usage or C2 communication patterns associated with Rokarolla. Endpoint protection solutions should be configured to flag apps requesting high-risk permissions, especially those distributed outside official app stores. Financial institutions may need to enhance fraud detection systems to account for the trojan’s ability to intercept SMS-based authentication codes.

Mitigation and recommendations

Zimperium, the mobile security firm that analyzed Rokarolla, confirmed the malware has not been found on Google Play. However, its distribution via third-party websites poses a significant risk to users who download APK files from untrusted sources. To reduce exposure, users should avoid sideloading apps unless they explicitly trust the publisher and verify the authenticity of download sources. Additionally, caution should be exercised when granting Accessibility permissions, as these can be exploited to bypass security controls and automate malicious actions.

Security teams are advised to review Zimperium’s GitHub repository, which documents all 137 commands used by Rokarolla. This resource can aid in developing detection signatures and understanding the malware’s full range of capabilities. Regular security awareness training for employees and customers can also help mitigate the risk of infection, particularly in organizations where mobile devices are used for financial transactions.

Companies mentioned

Zimperium Google

Discussion · coming soon

Be the first to join the thread when community discussion launches.