# New Rokarolla Android Banking Trojan Targets 217 Financial Apps With 137 Remote Commands


Security researchers at Zimperium's zLabs have uncovered a sophisticated new Android banking trojan dubbed Rokarolla that represents a significant escalation in mobile malware threats. The malware family targets over 217 banking and cryptocurrency applications, equips attackers with 137 distinct remote commands, and provides near-total control over compromised devices. By stealing PINs, intercepting SMS codes, hijacking clipboard data, and disabling security protections, Rokarolla exemplifies the growing sophistication of mobile financial malware.


## The Threat: What Rokarolla Does


Rokarolla operates as a full-featured banking trojan with a toolbox designed to compromise every layer of a user's financial security. The malware's primary capabilities include:


Financial Credentials and Authentication:

  • PIN and password theft via overlay attacks that capture unlock codes when users enter them
  • SMS interception to steal one-time passwords (OTPs) and two-factor authentication codes
  • Screen recording to capture sensitive user interactions
  • Keylogging to harvest typed credentials across apps and browser sessions

  • Direct Financial Manipulation:

  • Clipboard hijacking to intercept crypto addresses and redirect fund transfers to attacker-controlled wallets
  • App injection to overlay fake login screens on legitimate banking and payment apps
  • Transaction authorization by simulating user input once credentials are obtained
  • SMS spoofing to send fraudulent messages that appear to come from the user's phone

  • Device Control and Evasion:

  • Disabling Google Play Protect, Android's built-in malware defense
  • Stealing device credentials stored in system memory
  • Revoking permissions and silencing notifications to hide malicious activity
  • Disabling accessibility features to prevent users from detecting malware behavior

  • ## Technical Capabilities: 137 Remote Commands


    The scale of Rokarolla's command infrastructure is remarkable. With 137 distinct remote commands, the malware operates more as a mobile botnet client than a simple banking trojan. This command arsenal grants attackers:


  • Real-time monitoring of victim activity
  • Remote installation and execution of additional payloads
  • Fine-grained control over which apps to target at any given moment
  • Ability to adapt attack vectors based on victim device configuration
  • Communication protocols designed to evade network-level detection

  • The breadth of this command set suggests Rokarolla is built on a professional malware-as-a-service (MaaS) infrastructure, likely operated by a well-resourced threat actor or criminal organization. The 217 targeted financial applications span global banking institutions, regional financial services, and major cryptocurrency exchange platforms—indicating that operators are not narrowly focused but rather pursuing maximum victim monetization.


    ## Background and Context: Android's Persistent Malware Problem


    Rokarolla does not emerge in a vacuum. Android banking trojans have been a persistent and evolving threat for over a decade, with each new variant demonstrating tactical and technical improvements.


    Prior Notable Android Banking Trojans:


    | Malware Family | Year Discovered | Targeted Apps | Noteworthy Capability |

    |---|---|---|---|

    | Zeus | 2011 | ~50 banks | First major mobile banking trojan |

    | Spyeye | 2013 | Financial apps | Advanced man-in-the-middle attacks |

    | Banker.B | 2016 | ~100 financial apps | Overlay injection at scale |

    | Anubis | 2017 | 500+ financial apps | Ransomware variant |

    | Rokarolla | 2026 | 217 apps | 137 remote commands, clipboard hijacking |


    The progression from 50 targeted apps to 217, combined with the exponential growth in remote command capabilities, reflects the professionalization of mobile malware operations. Unlike older trojans that relied on hardcoded targets, Rokarolla can be remotely updated to attack new apps as they gain market share.


    ## How Rokarolla Spreads


    Zimperium's research does not yet detail the primary distribution vectors, but Android banking trojans typically use multiple infection methods:


  • Third-party app stores promoting apps with embedded malware payload
  • Social engineering disguised as legitimate banking apps, security software, or popular utilities
  • Exploit kits leveraging unpatched Android vulnerabilities
  • Phishing campaigns targeting specific financial institutions with convincing lures
  • SMS-based distribution using smishing tactics to deliver download links

  • The malware likely uses permissions obfuscation to hide its true functionality from the Google Play Store's automated scanning. Once installed, it can request permissions progressively, making detection by casual users less likely. The ability to disable Google Play Protect suggests the malware has evolved anti-analysis capabilities that allow it to detect and neutralize security mechanisms before they can act.


    ## Implications for Users and Organizations


    The emergence of Rokarolla has direct implications across three audiences:


    For Individual Users:

  • Every Android user who downloads banking or financial apps is a potential target
  • Crypto holders face unique risk, as clipboard hijacking can silently redirect transfers to attacker wallets
  • SMS codes no longer provide sufficient confidence in authentication security
  • Device PIN protection can be circumvented by malware running with system-level permissions

  • For Financial Institutions:

  • The expansion to 217 targeted apps suggests attackers are pursuing victims across multiple geographies and customer bases
  • Banks must assume that malware will continue to evolve overlay injection techniques
  • Traditional OTP-based 2FA is insufficient against malware with SMS access
  • Customer education about device security must escalate

  • For Cryptocurrency Platforms:

  • Crypto exchanges face disproportionate risk, as clipboard hijacking enables direct wallet-to-wallet theft
  • The appeal of cryptocurrency to attackers remains high, as transactions are often irreversible and pseudonymous
  • Platform-level defenses (e.g., withdrawal whitelisting) become more critical in a malware-heavy threat environment

  • ## Protection and Recommendations


    For Users:

  • Keep Android operating system and all apps updated to the latest versions
  • Download apps exclusively from the official Google Play Store, not third-party repositories
  • Review app permissions before installation; be skeptical of unusual requests
  • Enable Google Play Protect and keep it active
  • Use a reputable mobile security app with real-time malware detection
  • Consider biometric authentication (fingerprint or face recognition) in preference to PIN-based methods where available
  • Never grant accessibility service permissions to untrusted apps
  • Monitor financial accounts regularly for unauthorized activity

  • For Organizations:

  • Issue clear security policies prohibiting personal use of corporate financial apps on personal devices
  • Implement mobile device management (MDM) solutions to enforce security baselines
  • Deploy zero-trust authentication frameworks that assume device compromise
  • Use certificate pinning on banking apps to prevent man-in-the-middle attacks
  • Implement out-of-band authentication for sensitive transactions (e.g., confirmation via phone call)
  • Monitor for suspicious SMS activity and account access from unusual devices
  • Conduct regular security awareness training focused on mobile threats

  • ## HackWire Analysis


    The discovery of Rokarolla exposes a critical vulnerability in the mobile financial ecosystem: Android security has not kept pace with the sophistication of mobile banking malware. While Google has made incremental improvements to Play Protect and permission frameworks, the fundamental model—apps run with user-granted permissions and can access system resources like SMS—remains fundamentally broken for high-value targets.


    The 137 remote commands are the telling detail. This is not a malware variant that was built once and deployed unchanged. This is a living, evolving platform that can be instrumented and updated in real time to match defenders' countermeasures. The fact that it targets 217 apps simultaneously suggests a business model: attackers have monetized Rokarolla enough to justify ongoing development and operational costs. This is mature malware-as-a-service infrastructure.


    What other researchers are missing: Cryptocurrency targeting is now the highest-yield attack vector. Unlike banking trojans that must wait for users to log into their bank accounts and initiate transfers (which trigger fraud detection), crypto clipboard hijacking works silently. A user copies a wallet address, pastes it into a transfer dialog without noticing the substitution, and sends funds directly to attacker-controlled addresses. No fraud department, no chargebacks, no recovery. For attackers, this is asymmetric risk in their favor.


    The broader pattern: device-level compromise is now routine, and single-channel authentication is no longer secure. Organizations that still rely on SMS OTP for 2FA on sensitive financial systems are operating under assumption of breach. Rokarolla is just one variant; the Android malware ecosystem includes dozens of active banking trojans with overlapping capabilities.


    The immediate defensive priority for financial institutions: transition to authenticator apps, push-notification-based confirmation, or hardware security keys. SMS 2FA is theater. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)