Security researchers at Zimperium’s zLabs have documented a new Android banking trojan that targets 217 banking and cryptocurrency applications and carries 137 remote commands, giving an operator near-complete control of an infected phone. The malware, which Zimperium calls Rokarolla after its command-and-control infrastructure, can capture lock-screen PINs, read and send SMS messages, rewrite the clipboard to redirect cryptocurrency funds, and disable Google Play Protect.
Rokarolla spreads via malicious websites that impersonate popular applications such as TikTok and Chrome. The first component a victim installs is a dropper disguised as Google Play Protect, which uses that masquerade to install the main payload and gain Accessibility access. Once running, one of the trojan’s first commands turns Play Protect off, removing the first automated defense most Android users rely on.
Financial theft works through overlays. Rokarolla pulls a target list from its server, and for every banking or wallet app flagged as active, it downloads a fake HTML login page and stores it in a local database. When the victim opens the real app, the malware drops the fake page on top and captures everything typed into it, including card details and login credentials. A separate overlay mimics the Android lock screen to harvest the device’s PIN, pattern, or password, which lets the operator issue commands even while the phone is locked.
The trojan reads every SMS on the device and can send messages itself, which is enough to intercept the one-time codes banks use to authorize transactions. By making itself the default handler for texts and calls, it can also block incoming alerts or security notifications that might warn the victim about suspicious activity.
The crypto-wallet targeting is particularly aggressive: Rokarolla monitors the clipboard for cryptocurrency addresses and automatically replaces the destination address with one controlled by the attacker. This means a user copying a wallet address from an exchange or wallet app could end up sending funds to the attacker without noticing the swap.
Zimperium has shared indicators of compromise with Google, and Google Play Protect has been updated to detect the known variants. Users should be cautious of installation prompts from outside the Play Store and should verify that Google Play Protect is active on their devices.


