# New Rokarolla Android Banking Trojan Targets 217 Financial Apps With 137 Remote Commands
Security researchers at Zimperium's zLabs have uncovered a sophisticated new Android banking trojan dubbed Rokarolla that represents a significant escalation in mobile malware threats. The malware family targets over 217 banking and cryptocurrency applications, equips attackers with 137 distinct remote commands, and provides near-total control over compromised devices. By stealing PINs, intercepting SMS codes, hijacking clipboard data, and disabling security protections, Rokarolla exemplifies the growing sophistication of mobile financial malware.
## The Threat: What Rokarolla Does
Rokarolla operates as a full-featured banking trojan with a toolbox designed to compromise every layer of a user's financial security. The malware's primary capabilities include:
Financial Credentials and Authentication:
Direct Financial Manipulation:
Device Control and Evasion:
## Technical Capabilities: 137 Remote Commands
The scale of Rokarolla's command infrastructure is remarkable. With 137 distinct remote commands, the malware operates more as a mobile botnet client than a simple banking trojan. This command arsenal grants attackers:
The breadth of this command set suggests Rokarolla is built on a professional malware-as-a-service (MaaS) infrastructure, likely operated by a well-resourced threat actor or criminal organization. The 217 targeted financial applications span global banking institutions, regional financial services, and major cryptocurrency exchange platforms—indicating that operators are not narrowly focused but rather pursuing maximum victim monetization.
## Background and Context: Android's Persistent Malware Problem
Rokarolla does not emerge in a vacuum. Android banking trojans have been a persistent and evolving threat for over a decade, with each new variant demonstrating tactical and technical improvements.
Prior Notable Android Banking Trojans:
| Malware Family | Year Discovered | Targeted Apps | Noteworthy Capability |
|---|---|---|---|
| Zeus | 2011 | ~50 banks | First major mobile banking trojan |
| Spyeye | 2013 | Financial apps | Advanced man-in-the-middle attacks |
| Banker.B | 2016 | ~100 financial apps | Overlay injection at scale |
| Anubis | 2017 | 500+ financial apps | Ransomware variant |
| Rokarolla | 2026 | 217 apps | 137 remote commands, clipboard hijacking |
The progression from 50 targeted apps to 217, combined with the exponential growth in remote command capabilities, reflects the professionalization of mobile malware operations. Unlike older trojans that relied on hardcoded targets, Rokarolla can be remotely updated to attack new apps as they gain market share.
## How Rokarolla Spreads
Zimperium's research does not yet detail the primary distribution vectors, but Android banking trojans typically use multiple infection methods:
The malware likely uses permissions obfuscation to hide its true functionality from the Google Play Store's automated scanning. Once installed, it can request permissions progressively, making detection by casual users less likely. The ability to disable Google Play Protect suggests the malware has evolved anti-analysis capabilities that allow it to detect and neutralize security mechanisms before they can act.
## Implications for Users and Organizations
The emergence of Rokarolla has direct implications across three audiences:
For Individual Users:
For Financial Institutions:
For Cryptocurrency Platforms:
## Protection and Recommendations
For Users:
For Organizations:
## HackWire Analysis
The discovery of Rokarolla exposes a critical vulnerability in the mobile financial ecosystem: Android security has not kept pace with the sophistication of mobile banking malware. While Google has made incremental improvements to Play Protect and permission frameworks, the fundamental model—apps run with user-granted permissions and can access system resources like SMS—remains fundamentally broken for high-value targets.
The 137 remote commands are the telling detail. This is not a malware variant that was built once and deployed unchanged. This is a living, evolving platform that can be instrumented and updated in real time to match defenders' countermeasures. The fact that it targets 217 apps simultaneously suggests a business model: attackers have monetized Rokarolla enough to justify ongoing development and operational costs. This is mature malware-as-a-service infrastructure.
What other researchers are missing: Cryptocurrency targeting is now the highest-yield attack vector. Unlike banking trojans that must wait for users to log into their bank accounts and initiate transfers (which trigger fraud detection), crypto clipboard hijacking works silently. A user copies a wallet address, pastes it into a transfer dialog without noticing the substitution, and sends funds directly to attacker-controlled addresses. No fraud department, no chargebacks, no recovery. For attackers, this is asymmetric risk in their favor.
The broader pattern: device-level compromise is now routine, and single-channel authentication is no longer secure. Organizations that still rely on SMS OTP for 2FA on sensitive financial systems are operating under assumption of breach. Rokarolla is just one variant; the Android malware ecosystem includes dozens of active banking trojans with overlapping capabilities.
The immediate defensive priority for financial institutions: transition to authenticator apps, push-notification-based confirmation, or hardware security keys. SMS 2FA is theater. — HackWire Editorial
## Related Coverage