Security researchers have discovered a new Android malware strain dubbed ‘Rokarolla’ that targets 217 banking applications and cryptocurrency wallets, posing a significant threat to mobile financial security. The malware employs sophisticated overlay attacks and accessibility service abuse to steal login credentials and intercept two-factor authentication codes.
Rokarolla operates by masquerading as a legitimate system update or utility app. Once installed, it requests extensive permissions including accessibility service access, which Android grants to assistive technologies. The malware then monitors the user’s activity and, when a targeted banking or crypto app is launched, displays a fake login screen over the legitimate application. Unsuspecting users enter their credentials on this fake screen, which are then transmitted to the attacker’s command-and-control server.
What sets Rokarolla apart from earlier Android banking trojans is its extensive target list. The 217 targeted apps span major banks across Europe, North America, and Asia, along with popular cryptocurrency exchanges and wallet providers including Binance, Coinbase, MetaMask, and Trust Wallet. The malware also targets email apps and social media platforms to expand its credential harvesting capabilities.
Rokarolla also includes keylogging functionality, SMS interception for stealing 2FA codes, and the ability to record screen activity. It can hide its icon from the app drawer and maintain persistence through device reboots. The malware communicates with its C2 server using encrypted channels, making network-based detection more challenging.
Security experts recommend Android users take several precautions: only install apps from the Google Play Store, carefully review app permissions before granting them, keep Google Play Protect enabled, and avoid clicking on suspicious links or installation prompts from unknown sources. Users should also enable two-factor authentication through authenticator apps rather than SMS when possible.
Google has been notified about the malware and is reportedly updating Play Protect detection rules. Users who suspect infection should run a full device scan with a reputable mobile security solution and consider a factory reset if malicious activity is confirmed.


